Getting Data In

moving "spath" from query to config file

splunk_worker
Path Finder

Hi All
I want to move the spath from search query to the auto extraction configuration ie in props.conf and transforms.conf. Is this possible?

index=myindex | rex max_match=0 "(?{[^}]+})" | mvexpand json_field |spath input=json_field

spath breaks KV from complex JSON too. Hence I want use spath, but in configuration files instead of search query.

cpride_splunk
Splunk Employee
Splunk Employee

Given the fact that spath is happening after mvexpand and a rex -- I'm not sure it helps.

However if you were trying to basically have a single automatically extracted path command:

search foo=* | spath input=foo output=bar path=a.b

That is equivalent to (Spath Eval Function😞

search foo=* | eval bar=spath(foo, "a.b")

And you can embed that eval as a calculated field (Define Calculated Fields) to make it automatically extracted.

GauravSplunxter
Explorer

I embedded in props.conf and not getting the results.
EVAL-bar = spath(foo, "a.b")
What am I doing wrong?

0 Karma

camillak
Path Finder

Did you set the stanza correctly? eg: [source::your_source]

Also the parse won't show up in an Events search, need to table or similar.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...