You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将SonarQube分支指标JSON转换为Splunk表格?

正确的Splunk查询实现方法

原查询存在几个关键问题:一是引用了错误的JSON路径(比如measures.metrics{}.name,实际你的指标数组是measures.component.measures,且指标名称字段是metric而非name);二是没有处理period嵌套结构里的指标值。以下是修正后的查询:

index=sonar_dev sourcetype="sonarqube:branch:metrics"
| spath path=branch output=Branchname
| spath path=measures.component.name output=ProjectName  // 若项目名称存于key字段则替换为measures.component.key
| spath path=measures.component.measures{} output=measures_array
| mvexpand measures_array
| spath input=measures_array
| eval metric_value = if(isnotnull(period.value), period.value, value)
| eval project_branch = ProjectName . " - " . Branchname
| xyseries project_branch, metric, metric_value
| rename project_branch as "项目-分支"

步骤说明:

  1. spath path=branch output=Branchname:提取分支名称到单独字段
  2. spath path=measures.component.name output=ProjectName:提取项目名称(根据实际JSON结构调整字段路径)
  3. spath path=measures.component.measures{} output=measures_array:将嵌套的指标数组提取为多值字段
  4. mvexpand measures_array:把多值字段展开为单行,每个指标单独占一行
  5. spath input=measures_array:解析单行内的指标JSON,提取metric、value、period.value等字段
  6. eval metric_value = if(isnotnull(period.value), period.value, value):优先取period内的指标值,无则直接使用value字段
  7. eval project_branch = ProjectName . " - " . Branchname:组合项目与分支名称,作为表格的行标识
  8. xyseries project_branch, metric, metric_value:将metric转为列名,对应指标值作为单元格内容,实现横向表格效果
  9. rename project_branch as "项目-分支":将字段名改为中文,提升可读性

内容的提问来源于stack exchange,提问作者wehelpdox

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 19:17:09