Need to count/extract nested json arrays.


1 comment

  • Official comment
    Jorge Silva

    Hello Mike

    Give this query a try:

    | parse regex field=_raw "(?<message2>\{.+)(?:\,|])" multi
    | json field=message2 "type"
    | where type="blocked"

    I put the keyword "blocked" in the scope line of the query to only return messages that include this keyword. Then we use a parse regex with the multi option to split all the nested arrays into their own individual message for ease of handling. Then we use JSON parsing to parse out the field type and only the messages that include it and finally a where statement to return only the message where the field "type" equals "blocked".

    You can now continue working with the fields found in the message2 column.

    Comment actions Permalink

Please sign in to leave a comment.