Splunk Search

data format {"key1":"value1","key2":"value2"} Field extraction

kedjjang
Path Finder

key1 , key2 <<<<<= fields

The key may not enter any data.

Tags (1)
0 Karma

somesoni2
Revered Legend

Is your log file format is JSON?

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Difficult to tell what you actually want... but I am gonna guess that looking at the doc for spath will help you perhaps solve the problem or at least form the rest of the question:

http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/spath

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...