Splunk Search

Extracting field as a json object

vpsierra
Loves-to-Learn Lots

I am trying to extract a field(json array having objects) from events, now I would like to extract few more fields from that json array

[
{
"name": "a",
"age": "19",
"date_populated": "02/20/2019"

},
{
"name": "b",
"age": "23",
"date_populated": "02/25/2019"
}

]

 

can you please let me know how I can get a list of names

Labels (1)
0 Karma

to4kawa
Ultra Champion
index=_internal | head 1 | fields _raw _time | eval _raw="[
{
\"name\": \"a\",
\"age\": \"19\",
\"date_populated\": \"02/20/2019\"

},
{
\"name\": \"b\",
\"age\": \"23\",
\"date_populated\": \"02/25/2019\"
}

]"
| rename COMMENT as "the logic"

| spath {} output=root
| mvexpand root
| spath input=root
| table name age date_populated
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...