...as shown below but how to further extract the list of Recipients within it ?
I am trying below searches but no luck
| spath output=Recipients path=O...
Hello! As the subject of the question says, I'm trying to create SPL queries for several visualizations but it has become very tedious since spath does not work with the outputted events, as they c...
...018
}
]
}
]
}
I guess my issue is the SPATHing and linking the fields. If I Spath to Projects{}.Tasks{} I get two events with three Tasks in the first event and two tasks in the second event, which I w...
Hey Splunkers! We are running into an issue with an on-prem distributed deployment where the AWS feed is not extracting nested JSON fields at search time without the use of spath. We get first l...
...imes the ab_score =2/4 and then get the corresponding score=6.5 for each os_version. But when i am using spath and mvexpand i am getting 2/4 for all ab_score and all a_id. not u...
Hello, I have seen a few of the spath topics around, but wasn't able to understand enough to make it work for my data. I would like to create a line chart using pointlist v...
Hi Team I have the below Json string coming as an event in Splunk logs . after data, the next field could be a, b, c, d I want to read the x and y fields, How to write a single spath query l...
Hi i have xml file like this, how can i table it with xpath or spath? <?xml version="1.0" encoding="UTF-8" standalone="yes"?> <info xmlns:xsi="http://www.w3.org/2001/XMLSchema-i...
Hi, I wonder whether someone may be able to help me please.
I'm trying to create a query which extracts given values using 'spath'.
This is what I've come up with so far:
| multisearch
[ s...
eval FunctionalRef=spath(_raw,"n2:EvtMsg.Bd.BOEvt.Evt.DatElGrp{2}.DatEl.Val") -> I am getting two(2) values DHL5466256965140262WH3, DE4608089. Instead I should get only&n...