You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Splunk中提取嵌套JSON数组内的数据并实现表格展示

Splunk嵌套数组展平为表格解决方案

核心查询语句

index=你的索引 sourcetype=你的数据源
| mvexpand StopData
| spath input=StopData output=level path=level
| spath input=StopData output=code path=code
| spath input=StopData output=description path=description
| spath input=StopData output=detail path=detail
| table Id level code description detail

命令说明

  • mvexpand StopData:将StopData字段中的数组拆分为多行,每行对应数组中的一个对象,同时保留原事件的Id字段。
  • spath input=StopData output=xxx path=xxx:从展开后的单个StopData对象中提取指定字段(level、code等),并将其设置为独立的顶级字段。
  • table Id level code description detail:指定最终要展示的列,生成统一的长表格。

注意事项

  • 如果你的StopData字段是原始JSON字符串而非Splunk已解析的字段,需要先通过spath解析整个字段:
    index=你的索引 sourcetype=你的数据源
    | spath input=StopData  # 先解析整个数组字段
    | mvexpand StopData
    | spath input=StopData output=level path=level
    | table Id level code description detail
    
  • 确保字段名和路径完全匹配你的数据结构,比如如果对象内的字段是驼峰或下划线格式,要对应修改path参数。

内容的提问来源于stack exchange,提问作者stricq

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 18:25:39