Dear Community,
I am new to Splunk so apologies for the newbie question:
Basic Problem
I have a field which holds an Object and I am having difficulties retrieving a value from a specific key within this object.
Purpose
I am running a search and I want to retrieve two datetime values from two separate keys within a field, find the difference between these 2 datetime values and finally return a list of events where the difference is less than a particular value.
I know how to return a table of results based on a simple criteria and can perform datetime manipulations, I just cannot retrieve the actual datetime values needed to make the calculation.
*I can successfully store the whole object to a variable using the eval command but cannot extract the value from it.
Assumptions
The thing I am working with is indeed an Object. I.e. a dictionary style list in the following format
{"key1" : "value" , "key2" : "value" , "key2" : "value"}
I am attempting to extract the value using the eval command
Any help would be greatly appreciated.
Kind regards,
Ben
... View more