This is in follow-up to https://answers.splunk.com/answers/578105/help-with-search-to-access-json-data.html#comment-577285
Please find the attached image for sample event.
The query provided by is returning :- ABC.machine_cat:_attributes.ID.ABC.machine_cat
`<>`
_attributes.ID.ABC.machine_cat
`<>`
ABC.machine_cat
I want ABC.machine_cat : `<>`
Example: ABC.machine_cat : 01
![alt text][1]
[1]: /storage/temp/216684-123.png
↧