<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log level extraction in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525240#M3844</link>
    <description>&lt;P&gt;here is some sample data, can someone help me with a regular expression to extract the highlighted part "&lt;STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;status:READY_TO_PROCESS"&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;as process status&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2020-10-18&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:06:18&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;bp-&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class="t"&gt;507bbd99&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-completeMachineRun-233466&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;HitService&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Created&lt;/SPAN&gt; &lt;SPAN class="t"&gt;typed&lt;/SPAN&gt; &lt;SPAN class="t"&gt;run&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Run:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;id=233467&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;uuid=7653767a-5e85-409d-aa3e-69bbeac40ad0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;name=Final&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Results&lt;/SPAN&gt;&lt;SPAN&gt; {&lt;/SPAN&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;size&lt;/SPAN&gt;:&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;status:READY_TO_PROCESS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;rootRun:7653767a-5e85-409d-aa3e-69bbeac40ad0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;data:}&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Oct 2020 13:04:25 GMT</pubDate>
    <dc:creator>sphiwee</dc:creator>
    <dc:date>2020-10-18T13:04:25Z</dc:date>
    <item>
      <title>Log level extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525240#M3844</link>
      <description>&lt;P&gt;here is some sample data, can someone help me with a regular expression to extract the highlighted part "&lt;STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;status:READY_TO_PROCESS"&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;as process status&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2020-10-18&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:06:18&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;bp-&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class="t"&gt;507bbd99&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-completeMachineRun-233466&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;HitService&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Created&lt;/SPAN&gt; &lt;SPAN class="t"&gt;typed&lt;/SPAN&gt; &lt;SPAN class="t"&gt;run&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Run:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;id=233467&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;uuid=7653767a-5e85-409d-aa3e-69bbeac40ad0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;name=Final&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Results&lt;/SPAN&gt;&lt;SPAN&gt; {&lt;/SPAN&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;size&lt;/SPAN&gt;:&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;status:READY_TO_PROCESS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;rootRun:7653767a-5e85-409d-aa3e-69bbeac40ad0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;data:}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 13:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525240#M3844</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-18T13:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Log level extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525242#M3845</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I expecting that there is always word status and then it’s value ending to ,. If this is not a valid expectation then this rex needs to updated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;...
| rex "(?&amp;lt;status&amp;gt;status:[^,]+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 14:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525242#M3845</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-18T14:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Log level extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525246#M3846</link>
      <description>&lt;P&gt;Sorry but it's pulling something totally different&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 13:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525246#M3846</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-18T13:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Log level extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525247#M3847</link>
      <description>Sorry but it's pulling something totally different</description>
      <pubDate>Sun, 18 Oct 2020 14:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525247#M3847</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-18T14:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log level extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525248#M3848</link>
      <description>Forget + from the end, did it works now?</description>
      <pubDate>Sun, 18 Oct 2020 14:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525248#M3848</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-18T14:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Log level extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525253#M3850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;&amp;nbsp;...&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;'s rex query is working fine and extracting the status msg(did you add the plus sign and the field=_raw or ur fieldname?). Please check the screenshot:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval log="2020-10-18 14:06:18 [bp-[507bbd99]-completeMachineRun-233466] HitService [INFO] Created typed run Run: id=233467, uuid=7653767a-5e85-409d-aa3e-69bbeac40ad0 name=Final Results {size:0, status:READY_TO_PROCESS, rootRun:7653767a-5e85-409d-aa3e-69bbeac40ad0, data:}" 
| rex field=log "(?&amp;lt;status&amp;gt;status:[^,]+)" | table status&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rex-status.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11350i40A3A38CCFC4AF0B/image-size/large?v=v2&amp;amp;px=999" role="button" title="rex-status.jpg" alt="rex-status.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 16:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-level-extraction/m-p/525253#M3850</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-18T16:38:19Z</dc:date>
    </item>
  </channel>
</rss>

