You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Splunk中提取JSON格式功能开关数据并生成表格

在Splunk中提取JSON格式的功能开关数据并生成表格

我在Splunk中有一条包含JSON数据的事件,记录了一系列功能开关(feature toggles)的状态,事件内容如下:

2023-01-05 15:59:00,025 INFO  [com.example.FeatureToggleRepository] (executor-thread-4) {correlationId=efe2d0be-a4bc-4555-9ef3-cc640a107208, sampled=true, spanId=b200d532717a1a3b, traceId=020c59784f3f5624917ccf12defbc00a} {"featureToggles":[{"id":1,"updatedAt":"2023-01-05T14:59:00.010+00:00","createdAt":"2023-01-05T14:59:00.010+00:00","feature":"FEATURE_1","enabled":true},{"id":12,"updatedAt":"2023-01-05T14:52:46.614+00:00","createdAt":"2023-01-05T14:52:46.614+00:00","feature":"SOME_FEATURE","enabled":true}]}

我需要提取这些数据,生成包含id、feature、enabled列的表格,尝试了很多示例都没成功,求帮助。

最终可行的查询语句

以下是实现需求的Splunk查询语句:

...query...
| rex field=_raw max_match=0 "id\W+(?<id>\d+)"
| rex field=_raw max_match=0 "updatedAt\W+(?<updated>[^\"]+)"
| rex field=_raw max_match=0 "createdAt\W+(?<created>[^\"]+)"
| rex field=_raw max_match=0 "feature\W+(?<feature>[^\"]+)"
| rex field=_raw max_match=0 "enabled\W+(?<enabled>\w+)"
| eval an_event=mvzip(mvzip(mvzip(mvzip(id,updated,";"),created,";"),feature,";"),enabled,";")
| fields - id updated created feature enabled
| mvexpand an_event
| rex field=an_event "(?<id>[^;]+);(?<updated>[^;]+);(?<created>[^;]+);(?<feature>[^;]+);(?<enabled>.+)"
| table id feature enabled

语句逻辑说明

  1. 批量提取字段:通过rex命令配合max_match=0,从原始事件中提取所有匹配的id、updatedAt、createdAt、feature、enabled值,每个字段生成对应的多值字段;
  2. 绑定多值字段:使用mvzip多层嵌套,将多个多值字段按对应位置绑定,合并成一个以分号分隔的多值字段an_event;
  3. 展开为单行事件:用mvexpand将合并后的多值字段拆分成单独的事件行;
  4. 拆分还原字段:再次使用rex将an_event中的内容按分号拆分,还原出各个字段的值;
  5. 生成目标表格:最后通过table命令筛选出需要的id、feature、enabled列,生成目标表格。

内容的提问来源于stack exchange,提问作者JacobOJ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 23:00:42