Is your log file format is JSON?
Difficult to tell what you actually want... but I am gonna guess that looking at the doc for spath will help you perhaps solve the problem or at least form the rest of the question:
http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/spath