@javiergn - This looks almost exactly like what I'm trying to do with some JSON data. I'm trying to understand what you're doing with the search, however, I'm not sure my skills in Splunk are up to the higher level explanation you've given.
I'm trying to go through the Splunk docs on spath to gain a better understanding but not having a great time of it. Can you maybe explain a bit more in detail how spath() is used with eval? What does "myJSON" represent as the first parameter in that first line? How does that related to | spath input=myJSON?
Thanks!
... View more