Do not treat structured data as text; regex is not an appropriate tool. I suspect that the text you posted is copied from Splunk's structured viewer, not in "RAW Text" format. Is this correct? If ...
See more...
Do not treat structured data as text; regex is not an appropriate tool. I suspect that the text you posted is copied from Splunk's structured viewer, not in "RAW Text" format. Is this correct? If it is the case, Splunk would have already given you a field named Properties.Activity, whose value is itself an escaped, but fully compliant JSON string. (This is not a preferred method to log data. Developers usually resort to escaped JSON when the field has combined JSON and non-JSON content.) All you should need to do is spath. | spath input=Properties.Activity Your sample data should give you these fields ActivityStatus ActivityType ClientId Data.parentSpanId Data.pcm.name Data.pcm.user_id Data.traceId OriginCreationTimestamp Properties.Activity COMPLETE CreateCashTransactionType 1126 88558259300b25e5 Transaction_Type_2892023143936842 2 9b57deb074fd41df69f90226cb03f499 2023-09-28T11:39:48.4840749+00:00 {"ClientId":"1126","TenantCode":"BL.Activities","ActivityType":"CreateCashTransactionType","Source":"Web Entry Form","SourcePath":null,"TenantContextId":"00-9b57deb074fd41df69f90226cb03f499-353e17ffab1a6d25-01","ActivityStatus":"COMPLETE","OriginCreationTimestamp":"2023-09-28T11:39:48.4840749+00:00","Data":{"traceId":"9b57deb074fd41df69f90226cb03f499","parentSpanId":"88558259300b25e5","pcm.user_id":2,"pcm.name":"Transaction_Type_2892023143936842"}} If Splunk doesn't give you Properties.Activities, please click "Raw Text" in Splunk search window and post in text. The following is a partial emulation based on your sample data and my assumption. You can play with it and compare with real data. | makeresults
| eval _raw = "{\"Properties\": {
\"ActionId\": \"533b531b-3078-448f-a054-7f54240962af\",
\"ActionName\": \"Pcm.ActivityLog.ActivityReceiver.Controllers.v1.ActivitiesController.Post (Pcm.ActivityLog.ActivityReceiver)\",
\"Activity\": \"{\\\"ClientId\\\":\\\"1126\\\",\\\"TenantCode\\\":\\\"BL.Activities\\\",\\\"ActivityType\\\":\\\"CreateCashTransactionType\\\",\\\"Source\\\":\\\"Web Entry Form\\\",\\\"SourcePath\\\":null,\\\"TenantContextId\\\":\\\"00-9b57deb074fd41df69f90226cb03f499-353e17ffab1a6d25-01\\\",\\\"ActivityStatus\\\":\\\"COMPLETE\\\",\\\"OriginCreationTimestamp\\\":\\\"2023-09-28T11:39:48.4840749+00:00\\\",\\\"Data\\\":{\\\"traceId\\\":\\\"9b57deb074fd41df69f90226cb03f499\\\",\\\"parentSpanId\\\":\\\"88558259300b25e5\\\",\\\"pcm.user_id\\\":2,\\\"pcm.name\\\":\\\"Transaction_Type_2892023143936842\\\"}}\"
}}"
| spath
``` data emulation above ```