Splunk Search

data format {"key1":"value1","key2":"value2"} Field extraction

kedjjang
Explorer

key1 , key2 <<<<<= fields

The key may not enter any data.

Tags (1)
0 Karma

somesoni2
Revered Legend

Is your log file format is JSON?

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Difficult to tell what you actually want... but I am gonna guess that looking at the doc for spath will help you perhaps solve the problem or at least form the rest of the question:

http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/spath

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma