Hi everyone
I´m new in splunk ,I need to get items from a json file but when i search in my file i see this in many parts and i don´t get all entities that i need.
How can i configure splunk to read json in only one event and so i can to get all entities ?
On image i have 3 events from same json file i need only one event and so get all entities from this json .
The general answer is to add | spath
to your search and go from there. That command has many options and you can call it multiple times with filtering and renaming steps between:
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath