Entire log is JSON - how can I parse it?



  • Avatar
    Christian Beedgen

    try this (and i agree, this could be easier/more obvious):

    | json field=_raw "name", "hostname", "pid", "message_id","message_type", "worker_id", "level", "msg", "time", "v"

  • Avatar
    Tom Ruggles

    Thank you Christian.  I finally got something working last night that was similar but yours is nicer.  I had 

    | parse "*" as parsed | json field=parsed "name","hostname","level","message_id","message_type","msg" nodrop | fields -parsed 

    And it looks like the where part works like this:

    | where message_type = "pending"

  • Avatar
    David Han

    I have a similar follow up question. If I also have a json but a nested json object that looks like -


    would this query work?

    csp-report | json field=_raw "csp-report.document-uri", "csp-report.referrer", "csp-report.violated-directive"

  • Avatar
    David Han

    Hi, are there any updates on this?


    I checked the JSON Operator docs, and I'm not sure how to parse this json.. Any help would be much appreciated.

  • Avatar
    David Han

    I figured it out.

    Here is the query that I used.


    | parse "{\"csp-report\":*" as jsonobject

    | json field=jsonobject "blocked-uri", "document-uri", "referrer", "violated-directive", "effective-directive", "status-code", "source-file" nodrop

    | fields -jsonobject

Please sign in to leave a comment.