Hello all, I'm having issues achieving to extract fields from a sample in Splunk. I went to "extract fields", I have the first one, but I don't know how to continue. Here the sample: [{"Type":...
See more...
Hello all, I'm having issues achieving to extract fields from a sample in Splunk. I went to "extract fields", I have the first one, but I don't know how to continue. Here the sample: [{"Type":"Attention","ABUSE":18,"GSD 24x7":1,"CLOUD":0,"DC":0,"ECL":0,"ITMS":0,"NET":0,"RFO":17,"Total":36},{"Type":"Active","ABUSE":0,"GSD 24x7":22,"CLOUD":38,"DC":5,"ECL":1,"ITMS":0,"NET":12,"RFO":2,"Total":80},{"Type":"Total","ABUSE":18,"GSD 24x7":23,"CLOUD":38,"DC":5,"ECL":1,"ITMS":0,"NET":12,"RFO":19,"Total":116},{"Type":"P1","ABUSE":0,"GSD 24x7":0,"CLOUD":0,"DC":0,"ECL":0,"ITMS":0,"NET":0,"RFO":6,"Total":6},{"Type":"P2","ABUSE":0,"GSD 24x7":1,"CLOUD":0,"DC":0,"ECL":0,"ITMS":0,"NET":0,"RFO":10,"Total":11},{"Type":"P3\/4","ABUSE":18,"GSD 24x7":0,"CLOUD":0,"DC":0,"ECL":0,"ITMS":0,"NET":0,"RFO":1,"Total":19}] From that, I would like to be able to calculate averages and sums up from the number, having two fields: - Team. Values: ABUSE, CLOUD, GSD 24x7, NET, RFO... - Type: Attention, Active... with this in the search | rex max_match=0 "(?<Type>((\.*:\")\w+))"| I got the Type, but no idea on how to proceed. Any ideas? Thank you all in advance.