<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If not condition in TIME_PREFIX in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353047#M64673</link>
    <description>&lt;P&gt;Hi  isha_rastogi,&lt;BR /&gt;
did you tried using regexes in TIME_PREFIX?&lt;BR /&gt;
something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = (50\=)|(60\=)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:54:29 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-09-30T02:54:29Z</dc:date>
    <item>
      <title>If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353045#M64671</link>
      <description>&lt;P&gt;I am working in the FIX log messages and have two fields that contain timestamps. I need to check for one field and if that is not present check for other field. I'm facing problem if both of the fields is present.&lt;/P&gt;

&lt;P&gt;Ex: I have 50=timestamp | 70=XYZ | 60=timestamp. &lt;/P&gt;

&lt;P&gt;I am trying to extract timestamp from 60 if that not present then 52 but not able to write the regex if both are present because 50 is coming before 60 everytime so it's taking 50 field as timestamp. &lt;/P&gt;

&lt;P&gt;TIME_PREFIX=(50=|60=)&lt;/P&gt;

&lt;P&gt;Any idea how can I do that if both are present.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 09:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353045#M64671</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-06-14T09:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353046#M64672</link>
      <description>&lt;P&gt;Hi  isha_rastogi,&lt;BR /&gt;
did you tried using regexes in TIME_PREFIX?&lt;BR /&gt;
something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = (50\=)|(60\=)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353046#M64672</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-30T02:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353047#M64673</link>
      <description>&lt;P&gt;Hi  isha_rastogi,&lt;BR /&gt;
did you tried using regexes in TIME_PREFIX?&lt;BR /&gt;
something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = (50\=)|(60\=)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353047#M64673</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-30T02:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353048#M64674</link>
      <description>&lt;P&gt;yes, problem here is if either 50 or 60 is present then regex works like charm but if both are present I need to extract it from 60 . But as field 50 is always coming before 60 regex is breaking once it gets matching pattern. I tried using below regex but didn't work as it starts looking for 50 or 60 and whenever 50 comes it breaks never looks for 60&lt;BR /&gt;
TIME_PREFIX = (60=)|(50=)&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 09:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353048#M64674</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-06-14T09:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353049#M64675</link>
      <description>&lt;P&gt;Hi isha_rastogi,,&lt;BR /&gt;
Try &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(s?)(50\=)|(60\=)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;using regex101.com I tested that when both the conditions are true, using &lt;CODE&gt;(s?)&lt;/CODE&gt; the second one is preferred.&lt;BR /&gt;
I don't know if this condition is applicable or not to TIME_PREFIX (in theory it should be a regex!).&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 09:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353049#M64675</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-06-14T09:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353050#M64676</link>
      <description>&lt;P&gt;Hi cusello ,&lt;/P&gt;

&lt;P&gt;thanks for your fast response. Not working for me as I can see its creating groups for both Group 1 for 50 group 2 for 60 &lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 10:01:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353050#M64676</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-06-14T10:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353051#M64677</link>
      <description>&lt;P&gt;I think you have selected global, so it's giving all the matches but in TIME_PREFIX we cant use that option&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 10:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353051#M64677</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-06-14T10:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353052#M64678</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = ^.*(50=|60=)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 16 Jun 2017 14:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353052#M64678</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-16T14:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: If not condition in TIME_PREFIX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353053#M64679</link>
      <description>&lt;P&gt;Worked !!! Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 15:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-not-condition-in-TIME-PREFIX/m-p/353053#M64679</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-06-16T15:05:26Z</dc:date>
    </item>
  </channel>
</rss>

