Hey everyone. Need some help breaking a json event that is ingested in the current nested json format: [
{
"title": "Bad Stuff",
"count": 2,
"matches": [
{
"EventID": 13,
"EventRecordID": 19700,
"User": "NT AUTHORITY\\SYSTEM"
},
{
"EventID": 16,
"EventRecordID": 21700,
"User": "NT AUTHORITY\\ADMIN"
}
]
},
{
"title": "Next Bad Stuff",
"count": 2,
"matches": [
{
"EventID": 14,
"EventRecordID": 19700,
"User": "NT AUTHORITY\\SYSTEM"
},
{
"EventID": 17,
"EventRecordID": 21700,
"User": "NT AUTHORITY\\ADMIN"
}
]
}
] Would like to break it into seperate events like this: {
"title": "Bad Stuff",
"count": 2,
"EventID": 13,
"EventRecordID": 19700,
"User": "NT AUTHORITY\\SYSTEM"
}
{
"title": "Bad Stuff",
"count": 2,
"EventID": 16,
"EventRecordID": 21700,
"User": "NT AUTHORITY\\ADMIN"
}
{
"title": "Next Bad Stuff",
"count": 2,
"EventID": 14,
"EventRecordID": 19700,
"User": "NT AUTHORITY\\SYSTEM"
}
{
"title": "Next Bad Stuff",
"count": 2,
"EventID": 17,
"EventRecordID": 21700,
"User": "NT AUTHORITY\\ADMIN"
} What would I need in my props.conf and transforms.conf to achieve this ? Thanks in advanced splunk community ! Cheers.
... View more