I am using a query below which gives me rules field
index=myindex| spath "Rules{}" output=rules |mvexpand rules
| table device ip rules | rex field=rules "\:(?<rule_name>[^\,]+)\,(?<rule_result>[^\,]+)"
rules field has data like below:
{"name": "Abc Def - 123", "result": true}
Now i want these two to be spitted into two fields rules_name and rules_result
Hi @surekhasplunk,
is this a duplicated question?
if not, see the answer in https://community.splunk.com/t5/Splunk-Search/rex-help/td-p/521426/jump-to/first-unread-message
Ciao.
Giuseppe