please try with extract command in to extract all fields splunk https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Extract ex : for your case ... | extract pairdelim="," , kvdelim="/":" OR ... | extract pairdelim="," , kvdelim="\":"
... View more