Dear All,
We have splunk index with data like pattern and the pattern was recently changed.
{"Feild1":"DATA1","Feild2":"DATA2","Feild3":"DATA3","Feild4":"DATA4"}
We have several dashboards using previous data pattern like below.
DATA1,DATA2,DATA3,DATA4
Looking for a way to filter out or suppress {"Feild1": "Feild2":.....} using splunk query's and feed output to dashboards.
Kindly suggest how this can be done.
Thanks
This looks like JSON of sorts - have you considered treating it as such?
In the meantime, you could use rex mode=sed
| rex mode=sed "s/\"Felid\d\"://g"
Hello,
This looks like JSON of sorts - have you considered treating it as such? - Not sure how to implement it.
| rex mode=sed "s/\"Felid\d\"://g" - how do we implement for multiple fields like Feild1, Field 2 etc?
Perhaps if you shared your actual events (anonymised as little as possible of course), we might be able to give more useful advise - as it stands, a generic question will usually get a generic response! 😎