Extracting Values from Json in Splunk Using Spath

Extracting Values from Json in Splunk Using Spath

I am trying following query

| makeresults | eval _raw="{\"records\":[{\"Name\":\"name\"},{\"Name\":\"worst_food\",\"Value\":\"salad\"},{\"Name\":\"ex-wife\",\"Value\":\"Tammy\"}]}" | spath

this returns table as like below in Splunk.

records{}.name records().value name salad worst_food Tammy ex-wife

But i am expecting value as like

records{}.name records().value name worst_food salad ex-wife Tammy

Anyone experienced this issue? could you please share some knowledge that how to derive expected result.

1 Answer

@Dhana

Can you please try this?

| makeresults 
| eval _raw="{\"records\":[{\"Name\":\"name\"},{\"Name\":\"worst_food\",\"Value\":\"salad\"},{\"Name\":\"ex-wife\",\"Value\":\"Tammy\"}]}" 
| spath path=records{} output=records | mvexpand records | rename records as _raw | kv | table Name Value

Thanks

0

Your Answer

By clicking “Post Your Answer”, you agree to our terms of service and acknowledge that you have read and understand our privacy policy and code of conduct.

Alexander Ross
Author

Alexander Ross

Alexander Ross has covered the video game industry for a decade, writing deep dives on game design, esports tournaments, VR developments, and gaming culture.