<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regex Extraction for Field in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Regex-Extraction-for-Field/m-p/579349#M11004</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From the below events i need to extract the field called "&lt;STRONG&gt;Event_Name&lt;/STRONG&gt;" which is associated with "&lt;STRONG&gt;BeyondTrust_PBUL_ACCEPT_Event&lt;/STRONG&gt;" from below 3 events&lt;/P&gt;&lt;P&gt;Desired output: Event_Name(&lt;STRONG&gt;filed name&lt;/STRONG&gt;)=BeyondTrust_PBUL_ACCEPT_Event(&lt;STRONG&gt;field value&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example Event 1:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;86&amp;gt;Dec 22 ddppvc0729 pbmerd2.1.0-12: BeyondTrust_PBUL_ACCEPT_Event: Time_Zone='IST'; Request_Date='2021/1/27'; Request_Time='2:2:51'; Request_End_Date='2021/1/27'; Request_End_Time='22:1:51';Submit_User='spnt'; Submit_Host='wcpl.com';&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example Event 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;83&amp;gt;Dec 22 ddpc0729 pbmerd21.1.0-12: [2658] 5105.1 failed to get ACK packet during a CMD_SWAPTTY_ONE_LINE sequence - read failure in receive acknowledgement&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example Event 3:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;38&amp;gt;Dec 22 ddppvc0729 root[25132]: [ID 7011 auth.info] CEF:0|BeyondTrust|PowerBroker|1.1.0-12|7011|PBEvent=Accept|4|act=Accept end=Dec 1 2021 1:11:40 shost=dc8 dvchost=dc8 suser=t8adsfk duser=root filePath=/opt/ cs1Label=Ticket cs1=Not_Applicable deviceExternalId=0a2adfersds9 fname=./SSB_Refresh_Pbrun_Local_Policy_Files.sh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What i tried from regex extraction:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Input: (?&amp;lt;Event_Name&amp;gt;\w{10}[a-zA-Z]+_[a-zA-Z]+_[a-zA-Z]+_[a-zA-Z]+)&lt;/P&gt;&lt;P&gt;Output: matching 2 places from above 3 events&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pchintha_0-1640663261600.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17347i22BA5D15437CBE77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pchintha_0-1640663261600.png" alt="pchintha_0-1640663261600.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Dec 2021 03:49:20 GMT</pubDate>
    <dc:creator>pchintha</dc:creator>
    <dc:date>2021-12-28T03:49:20Z</dc:date>
    <item>
      <title>Regex Extraction for Field</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Regex-Extraction-for-Field/m-p/579349#M11004</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From the below events i need to extract the field called "&lt;STRONG&gt;Event_Name&lt;/STRONG&gt;" which is associated with "&lt;STRONG&gt;BeyondTrust_PBUL_ACCEPT_Event&lt;/STRONG&gt;" from below 3 events&lt;/P&gt;&lt;P&gt;Desired output: Event_Name(&lt;STRONG&gt;filed name&lt;/STRONG&gt;)=BeyondTrust_PBUL_ACCEPT_Event(&lt;STRONG&gt;field value&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example Event 1:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;86&amp;gt;Dec 22 ddppvc0729 pbmerd2.1.0-12: BeyondTrust_PBUL_ACCEPT_Event: Time_Zone='IST'; Request_Date='2021/1/27'; Request_Time='2:2:51'; Request_End_Date='2021/1/27'; Request_End_Time='22:1:51';Submit_User='spnt'; Submit_Host='wcpl.com';&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example Event 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;83&amp;gt;Dec 22 ddpc0729 pbmerd21.1.0-12: [2658] 5105.1 failed to get ACK packet during a CMD_SWAPTTY_ONE_LINE sequence - read failure in receive acknowledgement&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example Event 3:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;38&amp;gt;Dec 22 ddppvc0729 root[25132]: [ID 7011 auth.info] CEF:0|BeyondTrust|PowerBroker|1.1.0-12|7011|PBEvent=Accept|4|act=Accept end=Dec 1 2021 1:11:40 shost=dc8 dvchost=dc8 suser=t8adsfk duser=root filePath=/opt/ cs1Label=Ticket cs1=Not_Applicable deviceExternalId=0a2adfersds9 fname=./SSB_Refresh_Pbrun_Local_Policy_Files.sh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What i tried from regex extraction:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Input: (?&amp;lt;Event_Name&amp;gt;\w{10}[a-zA-Z]+_[a-zA-Z]+_[a-zA-Z]+_[a-zA-Z]+)&lt;/P&gt;&lt;P&gt;Output: matching 2 places from above 3 events&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pchintha_0-1640663261600.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17347i22BA5D15437CBE77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pchintha_0-1640663261600.png" alt="pchintha_0-1640663261600.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 03:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Regex-Extraction-for-Field/m-p/579349#M11004</guid>
      <dc:creator>pchintha</dc:creator>
      <dc:date>2021-12-28T03:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Extraction for Field</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Regex-Extraction-for-Field/m-p/579402#M11013</link>
      <description>&lt;P&gt;Please clarify which part of each event is the Event_Name, especially Example 2.&lt;/P&gt;&lt;P&gt;Are the sample events from the same sourcetype?&amp;nbsp; They look very different, which means they can have different field extractions.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 16:32:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Regex-Extraction-for-Field/m-p/579402#M11013</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-28T16:32:20Z</dc:date>
    </item>
  </channel>
</rss>

