Hi guys, So I have a multi array json input. What I am looking to do is have it split the initial raw data into seperate JSON events. EX: { "response": { "method": "switchvox.callQueues....
See more...
Hi guys, So I have a multi array json input. What I am looking to do is have it split the initial raw data into seperate JSON events. EX: { "response": { "method": "switchvox.callQueues.getCurrentStatus", "result": { "call_queue": { "extension": "2070", "strategy": "ring_all", "queue_members": { "queue_member": [ { "paused_time": "1626", "completed_calls": "1", "paused_since": "2021-01-08 08:59:28", "talking_to_name": "", "login_type": "login", "order": "1", "login_time": "7265", "extension": "4826", "max_talk_time": "835", "time_of_last_call": "2021-01-08 08:26:32", "paused": "1", "account_id": "1503", "missed_calls": "0", "logged_in_status": "logged_in", "fullname": "", "talking_to_number": "", "avg_talk_time": "835" }, { "paused_time": "773", "completed_calls": "1", "paused_since": "", "talking_to_name": "", "login_type": "login", "order": "2", "login_time": "3713", "extension": "4824", "max_talk_time": "183", "time_of_last_call": "2021-01-08 08:13:34", "paused": "0", "account_id": "1587", "missed_calls": "1", "logged_in_status": "logged_in", "fullname": "", "talking_to_number": "", "avg_talk_time": "183" }, to { "paused_time": "1626", "completed_calls": "1", "paused_since": "2021-01-08 08:59:28", "talking_to_name": "", "login_type": "login", "order": "1", "login_time": "7265", "extension": "4826", "max_talk_time": "835", "time_of_last_call": "2021-01-08 08:26:32", "paused": "1", "account_id": "1503", "missed_calls": "0", "logged_in_status": "logged_in", "fullname": "", "talking_to_number": "", "avg_talk_time": "835" } and { "paused_time": "773", "completed_calls": "1", "paused_since": "", "talking_to_name": "", "login_type": "login", "order": "2", "login_time": "3713", "extension": "4824", "max_talk_time": "183", "time_of_last_call": "2021-01-08 08:13:34", "paused": "0", "account_id": "1587", "missed_calls": "1", "logged_in_status": "logged_in", "fullname": "", "talking_to_number": "", "avg_talk_time": "183" }, I think I need to use a transformation so this happens at indexing, but I am not sure how to do it while making sure Splunk still processes the resultant data and JSON.