I have the following JSON, but I'm not really familiar with Splunk's rex function.
I tried this command without success: | rex "(?{[^}]+})" | mvexpand json_field | spath input=json_field
[
{
"Eqpt Class Description": null,
"Eqpt Criticality": "D",
"Eqpt Criticality Desc": "Non Essential",
"Eqpt Description": null,
"Eqpt Type Description": "Instrumentation",
"Maint Plant Caption": null,
"Maint Plant Filter Code": null,
"Maint Plant ID": null
},
{
"Eqpt Class Description": null,
"Eqpt Criticality": "D",
"Eqpt Criticality Desc": "Non Essential",
"Eqpt Description": null,
"Eqpt Type Description": "Instrumentation",
"Maint Plant Caption": null,
"Maint Plant Filter Code": null,
"Maint Plant ID": null
},
{
"Eqpt Class Description": null,
"Eqpt Criticality": "D",
"Eqpt Criticality Desc": "Non Essential",
"Eqpt Description": null,
"Eqpt Type Description": "Instrumentation",
"Maint Plant Caption": null,
"Maint Plant Filter Code": null,
"Maint Plant ID": null
}
]
For me to be able to build a dashboard with it, I need that to be displayed similar as in:
Could someone please help me to parse this on "}, {"?
... View more