<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex for multiline events where skipping lines is required. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743879#M118170</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/130109"&gt;@TheJagoff&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im struggling a little to work out the boundaries between the events but I think I might have it now...Just to check - is it the last line in each event that you want to extract? If so the following might work well:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=100 field=_raw "(?m)(?&amp;lt;message&amp;gt;[^\n\r]+)$"
| eval last_line = mvindex(message, -1)&lt;/LI-CODE&gt;&lt;P&gt;Incase its useful for future responses, below is the full example with some makeresults to emulate your events.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|makeresults | eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server01.log.gz
Host key verification failed.
lost connection"
| append [|makeresults | eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server02.log.gz
You are attempting to access a system owned by XYZ
Provide proper credentials for access
Contact the system administrator for assistance
---This system is monitored---
Details as follows.
scp: /logs/rsyslog/server02/: Not a directory"]
| rex max_match=100 field=_raw "(?m)(?&amp;lt;message&amp;gt;[^\n\r]+)$"
| eval last_line = mvindex(message, -1)&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 09 Apr 2025 14:57:17 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-04-09T14:57:17Z</dc:date>
    <item>
      <title>Regex for multiline events where skipping lines is required.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743875#M118169</link>
      <description>&lt;P&gt;I have multiline events where it is required to capture the error messages.&lt;/P&gt;&lt;P&gt;The events are separated by "FAILED".&lt;/P&gt;&lt;P&gt;I need to capture "Host key verification failed" from the first event, "scp: /logs/rsyslog/server02/: Not a directory" from the second event.&lt;/P&gt;&lt;P&gt;The events:&lt;/P&gt;&lt;P&gt;FAILED to copy checksum for: /logs/archives/archived-logs/server01.log.gz&lt;BR /&gt;Host key verification failed.&lt;BR /&gt;lost connection&lt;BR /&gt;FAILED to copy checksum for: /logs/archives/archived-logs/server02.log.gz&lt;BR /&gt;You are attempting to access a system owned by XYZ&lt;BR /&gt;Provide proper credentials for access&lt;BR /&gt;Contact the system administrator for assistance&lt;BR /&gt;---This system is monitored---&lt;BR /&gt;Details as follows.&lt;BR /&gt;scp: /logs/rsyslog/server02/: Not a directory&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can capture the first message with:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;FAILE&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;D&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;\:&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s&lt;/SPAN&gt;&lt;SPAN class=""&gt;(?&amp;lt;LogFile&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;\n&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;(?&amp;lt;Message&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;\n&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I don't know how to skip to capture the last line of the second event for the Message field.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Any help is most appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 14:39:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743875#M118169</guid>
      <dc:creator>TheJagoff</dc:creator>
      <dc:date>2025-04-09T14:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiline events where skipping lines is required.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743879#M118170</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/130109"&gt;@TheJagoff&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im struggling a little to work out the boundaries between the events but I think I might have it now...Just to check - is it the last line in each event that you want to extract? If so the following might work well:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=100 field=_raw "(?m)(?&amp;lt;message&amp;gt;[^\n\r]+)$"
| eval last_line = mvindex(message, -1)&lt;/LI-CODE&gt;&lt;P&gt;Incase its useful for future responses, below is the full example with some makeresults to emulate your events.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|makeresults | eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server01.log.gz
Host key verification failed.
lost connection"
| append [|makeresults | eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server02.log.gz
You are attempting to access a system owned by XYZ
Provide proper credentials for access
Contact the system administrator for assistance
---This system is monitored---
Details as follows.
scp: /logs/rsyslog/server02/: Not a directory"]
| rex max_match=100 field=_raw "(?m)(?&amp;lt;message&amp;gt;[^\n\r]+)$"
| eval last_line = mvindex(message, -1)&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 14:57:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743879#M118170</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-09T14:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiline events where skipping lines is required.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743884#M118172</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; - I need the last 2 lines of the first event, and the last line of the second event. I honestly don't know if this is even possible.&lt;BR /&gt;The events start with "&lt;SPAN&gt;FAILED to copy checksum for:&amp;nbsp;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I will work with what you have sent and see what I get for results. Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 15:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743884#M118172</guid>
      <dc:creator>TheJagoff</dc:creator>
      <dc:date>2025-04-09T15:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiline events where skipping lines is required.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743886#M118173</link>
      <description>&lt;P&gt;What distinguishes the first event from the second? Assuming it is a line with "lost connection", you could try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server01.log.gz
Host key verification failed.
lost connection"
| append [| makeresults
| fields - _time
| eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server02.log.gz
You are attempting to access a system owned by XYZ
Provide proper credentials for access
Contact the system administrator for assistance
---This system is monitored---
Details as follows.
scp: /logs/rsyslog/server02/: Not a directory"]
| rex "(?m)FAILED to copy checksum for:[^\n]+\n([^\n]+\n)*(?!lost connection)(?&amp;lt;line&amp;gt;[^\n]+(\nlost connection|$))"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 09 Apr 2025 15:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743886#M118173</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-04-09T15:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiline events where skipping lines is required.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743889#M118175</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/130109"&gt;@TheJagoff&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about this?&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|makeresults | eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server01.log.gz
Host key verification failed.
lost connection"
| append [|makeresults | eval _raw="FAILED to copy checksum for: /logs/archives/archived-logs/server02.log.gz
You are attempting to access a system owned by XYZ
Provide proper credentials for access
Contact the system administrator for assistance
---This system is monitored---
Details as follows.
scp: /logs/rsyslog/server02/: Not a directory"]
| rex max_match=100 field=_raw "(?m)(?&amp;lt;message&amp;gt;[^\n\r]+)$"
| eval last_line = if(typeof(mvfind(message,"Details as follows"))=="Number","", mvindex(message,-2))+" "+mvindex(message, -1)&lt;/LI-CODE&gt;&lt;P&gt;It joins the last 2 lines by a space for event 1 - might need tweaking to add the linebreak back in.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 16:11:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743889#M118175</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-09T16:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiline events where skipping lines is required.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743893#M118176</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;. Both responses helped me understand the overall issue and I thank you both.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Another method that I worked on is to use 2 Regex expressions in props.conf:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Regex 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class=""&gt;FAILE&lt;/SPAN&gt;&lt;SPAN class=""&gt;D&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;\:&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s&lt;/SPAN&gt;&lt;SPAN class=""&gt;(?&amp;lt;LogFile&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;\n&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;(?&amp;lt;Reason1&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;\n&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN class=""&gt;&lt;FONT color="#FF0000"&gt;)&amp;nbsp;&lt;/FONT&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;- that grabs &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;"&lt;/SPAN&gt;Host key verification failed lost connection" OR "&lt;SPAN&gt;You are attempting to access a system owned by XYZ" into the Reason1 field&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The second Regex:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;FONT color="#FF0000"&gt;Agreement\sfor\sdetails\.(\n)(?&amp;lt;Reason2&amp;gt;.+)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;That grabs:&lt;/P&gt;&lt;P&gt;"scp: /logs/rsyslog/server02/: Not a directory&lt;FONT color="#000000"&gt;"&lt;/FONT&gt; into the Reason2 field&lt;/P&gt;&lt;P&gt;In the search there is a case statement to make it work&lt;/P&gt;&lt;P&gt;| eval Message=case(like(Reason1,"%You are%"),Reason2,1==1,Reason1)&lt;/P&gt;&lt;P&gt;It sounds a bit inefficient, but it is working for the report.&lt;/P&gt;&lt;P&gt;Thank you both again.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 18:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-for-multiline-events-where-skipping-lines-is-required/m-p/743893#M118176</guid>
      <dc:creator>TheJagoff</dc:creator>
      <dc:date>2025-04-09T18:29:37Z</dc:date>
    </item>
  </channel>
</rss>

