Hi, quite a beginner here with Splunk. Is there a way to simply extract all parameters in below JSON object? The parameters returned can change based on partner.
Search: host=tp* index=pie *Avianca* OR *AFKLM* OR *British* OR *Etihad* OR *Sears* OR *IHG* OR *JETBLUE* OR *JET* OR *CARLSON* OR *EMirates* OR *Atlantic* MemberValidation RSP_JSON
<2018-04-29 23:04:18,658> TR0414012531-675696 [0e775a48ffdb4b61ab03c6af6785805d]: [RSP_JSON] [/JetBlue_PointsCore/JetBlue/MemberValidation] {
"membershipLevel": "",
"memberId": "",
"status": "",
"partnerResponseMessage": "",
"firstName": "",
"lastName": "",
"accountStatus": "",
"membershipNumber": "",
"balance": ,
"partnerResponseCode": "",
"email": "",
"accountCreationDate": "",
"stage": ""
}
... View more