Skip to main content
Question

Extract into json objects together with the other _raw.items and rename the field

  • March 11, 2025
  • 9 replies
  • 98 views

Hello all,I need some help please. I have some data in _raw.body, and I'd like to extract the them into json objects together with the other _raw.items (such as _raw.ctupdate)I'd also like to rename some of the fields. Any suggestions?

9 replies

  • Participating Frequently
  • March 11, 2025

It looks like body has some Key:Value pairs.Have you tried using a Parser() function w/source field of _raw and Type of Delimited values?Where delimiter is `:`.


David Maislin

Regex is better for that use case


David Maislin

Jon Rust
Forum|alt.badge.img
  • Employee
  • March 11, 2025

I'm glad you posted that <@U01C35EMQ01&gt;. I will be needing that in the future. It's very similar to Splunk's method, so I'm glad to see it's available the same way. :slightly_smiling_face: :+1::skin-tone-2:


  • Author
  • Employee
  • March 11, 2025

Thanks <@U01C35EMQ01&gt;. I tried the solution, but get KEY_0: {"body" as an output


David Maislin

I Dm'd you a zoom


  • Author
  • Employee
  • March 11, 2025

sure


  • Participating Frequently
  • March 11, 2025

The world would be a better place with nicely formatted input. I don't think that David has met a poorly formatted input that he could not tame with Stream.


David Maislin

All fixed!