Hello! As the subject of the question says, I'm trying to create SPL queries for several visualizations but it has become very tedious since spath does not work with the outputted events, as they c...
...as shown below but how to further extract the list of Recipients within it ?
I am trying below searches but no luck
| spath output=Recipients path=O...
Hi Team I have the below Json string coming as an event in Splunk logs . after data, the next field could be a, b, c, d I want to read the x and y fields, How to write a single spath query l...
Hello, I have seen a few of the spath topics around, but wasn't able to understand enough to make it work for my data. I would like to create a line chart using pointlist v...
...imes the ab_score =2/4 and then get the corresponding score=6.5 for each os_version. But when i am using spath and mvexpand i am getting 2/4 for all ab_score and all a_id. not u...
...018
}
]
}
]
}
I guess my issue is the SPATHing and linking the fields. If I Spath to Projects{}.Tasks{} I get two events with three Tasks in the first event and two tasks in the second event, which I w...
Hey Splunkers! We are running into an issue with an on-prem distributed deployment where the AWS feed is not extracting nested JSON fields at search time without the use of spath. We get first l...
I have a log file that is coming into splunk in json format. There appear to be two fields of interest, "key" and "value."
key: originid origintype template starttime endtime...
Hi i have xml file like this, how can i table it with xpath or spath? <?xml version="1.0" encoding="UTF-8" standalone="yes"?> <info xmlns:xsi="http://www.w3.org/2001/XMLSchema-i...
Hi All -
I am working with a very simple database that stores lists of key=value pairs with a potential expiration date and provides a REST API that outputs this data in JSON.
I've played with spath...