在Splunk中提取嵌套JSON数组内的数据并实现表格展示
Splunk嵌套数组展平为表格解决方案
核心查询语句
index=你的索引 sourcetype=你的数据源 | mvexpand StopData | spath input=StopData output=level path=level | spath input=StopData output=code path=code | spath input=StopData output=description path=description | spath input=StopData output=detail path=detail | table Id level code description detail
命令说明
mvexpand StopData:将StopData字段中的数组拆分为多行,每行对应数组中的一个对象,同时保留原事件的Id字段。spath input=StopData output=xxx path=xxx:从展开后的单个StopData对象中提取指定字段(level、code等),并将其设置为独立的顶级字段。table Id level code description detail:指定最终要展示的列,生成统一的长表格。
注意事项
- 如果你的StopData字段是原始JSON字符串而非Splunk已解析的字段,需要先通过
spath解析整个字段:index=你的索引 sourcetype=你的数据源 | spath input=StopData # 先解析整个数组字段 | mvexpand StopData | spath input=StopData output=level path=level | table Id level code description detail - 确保字段名和路径完全匹配你的数据结构,比如如果对象内的字段是驼峰或下划线格式,要对应修改
path参数。
内容的提问来源于stack exchange,提问作者stricq
相关产品推荐
相关产品推荐

