<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regex to extract multivalue and null values from the fields. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-multivalue-and-null-values-from-the-fields/m-p/526653#M88823</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I would need your help in extracting multi field values from the below sample. I have a regex below which is not helping me in extracting multi field values, It's just extracting first value from the&amp;nbsp; below log sample. So could you help me in modifying the regex please? Thanks in advance.&lt;/P&gt;&lt;P&gt;Regex: \w+[\s+\-\:\w+]*=(?:[^\\,]+)*&lt;/P&gt;&lt;P&gt;e.g. multivalue field is dhcp-parameter-request-list=1\, 22\, 3\, 4\, 77\, 55\, 99\, 200\,&lt;/P&gt;&lt;P&gt;Current Result:&amp;nbsp;dhcp-parameter-request-list=1 (Pls note just 1 is extracted from my regex but i would need other values i.e. 22, 3, 4, 77, 55, 77, 99 and 200 to get extracted as well)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log source Sample:&lt;/P&gt;&lt;P&gt;Oct 19 16:55:17 xxxxx33 xxx_profiler 000324 1 0 2020-10-19 16:55:17:108 +01:00 000628 80002 INFO Profiler: Profiler Endpoint Profiling event occured, configversionid=xxxx, Endpointcertainitymetric=50, EndpointIPAddress=xx.xx.xx.xxx, EndpointProperty=dhcp-class-identifier=xx.xxx.com\, Policyversion=000\, AuthenticationIdentityStore=Internal Endpoints\, lldpcachecapabilities=B\;T\, EndpointPolicyID=xxx-xxx-xxxxx\, LogicalProfile=xxx-xxx-xx\, xxx-xxxx-xxxx\, AuthenticationMethod=lookup\, FirstCollection=1518577\, CacheUpdateTime=10000\, IdentityAtoreGUID=\, StaticAssignment=false\, UserName=xxx\, NmapScanCpunt=0\, NetwrokDeviceName=xx.xx.xx.com\, DestIPAddress=xx.xx.xxx.xx\, AAA-Server=xxx\,&lt;BR /&gt;MessageCode=000\, Device Type= Device Type#All Device Types\,PortalUser=\, AllowedProtocalMatchedRule=Wired_MM\, ciaddre=x.x.x.x\, BYODRegistration=Unknown\, Calling-Station-ID=xx-xx-xx-xx\, dhcp-requested-address=xx.xx.xx.xx\, FailureReason=-\, dhcp-parameter-request-list=1\, XX\, X\, X\, XX\, XX\, XX\, XXX\, PostureApplicable=Yes\, Description=Voice:XXX Phones Caanry Waref #VLAN:IPT-VOICE#TYPE:VOICE#SYNC:1.0\, phoneID=\, hostname=xxxx\, NAS-Port-Id=Gigabit Ethernet/x/xx\, location=location #all locations#\, uniquesubjectid=, EndpointSourceEvent=DNS Probe, EndpointIdentityGroup=xxx_Phones, ProfileServer=xx.xx.xx.xx,&lt;/P&gt;</description>
    <pubDate>Tue, 27 Oct 2020 14:09:21 GMT</pubDate>
    <dc:creator>firefox95</dc:creator>
    <dc:date>2020-10-27T14:09:21Z</dc:date>
    <item>
      <title>Regex to extract multivalue and null values from the fields.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-multivalue-and-null-values-from-the-fields/m-p/526653#M88823</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;I would need your help in extracting multi field values from the below sample. I have a regex below which is not helping me in extracting multi field values, It's just extracting first value from the&amp;nbsp; below log sample. So could you help me in modifying the regex please? Thanks in advance.&lt;/P&gt;&lt;P&gt;Regex: \w+[\s+\-\:\w+]*=(?:[^\\,]+)*&lt;/P&gt;&lt;P&gt;e.g. multivalue field is dhcp-parameter-request-list=1\, 22\, 3\, 4\, 77\, 55\, 99\, 200\,&lt;/P&gt;&lt;P&gt;Current Result:&amp;nbsp;dhcp-parameter-request-list=1 (Pls note just 1 is extracted from my regex but i would need other values i.e. 22, 3, 4, 77, 55, 77, 99 and 200 to get extracted as well)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log source Sample:&lt;/P&gt;&lt;P&gt;Oct 19 16:55:17 xxxxx33 xxx_profiler 000324 1 0 2020-10-19 16:55:17:108 +01:00 000628 80002 INFO Profiler: Profiler Endpoint Profiling event occured, configversionid=xxxx, Endpointcertainitymetric=50, EndpointIPAddress=xx.xx.xx.xxx, EndpointProperty=dhcp-class-identifier=xx.xxx.com\, Policyversion=000\, AuthenticationIdentityStore=Internal Endpoints\, lldpcachecapabilities=B\;T\, EndpointPolicyID=xxx-xxx-xxxxx\, LogicalProfile=xxx-xxx-xx\, xxx-xxxx-xxxx\, AuthenticationMethod=lookup\, FirstCollection=1518577\, CacheUpdateTime=10000\, IdentityAtoreGUID=\, StaticAssignment=false\, UserName=xxx\, NmapScanCpunt=0\, NetwrokDeviceName=xx.xx.xx.com\, DestIPAddress=xx.xx.xxx.xx\, AAA-Server=xxx\,&lt;BR /&gt;MessageCode=000\, Device Type= Device Type#All Device Types\,PortalUser=\, AllowedProtocalMatchedRule=Wired_MM\, ciaddre=x.x.x.x\, BYODRegistration=Unknown\, Calling-Station-ID=xx-xx-xx-xx\, dhcp-requested-address=xx.xx.xx.xx\, FailureReason=-\, dhcp-parameter-request-list=1\, XX\, X\, X\, XX\, XX\, XX\, XXX\, PostureApplicable=Yes\, Description=Voice:XXX Phones Caanry Waref #VLAN:IPT-VOICE#TYPE:VOICE#SYNC:1.0\, phoneID=\, hostname=xxxx\, NAS-Port-Id=Gigabit Ethernet/x/xx\, location=location #all locations#\, uniquesubjectid=, EndpointSourceEvent=DNS Probe, EndpointIdentityGroup=xxx_Phones, ProfileServer=xx.xx.xx.xx,&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 14:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-multivalue-and-null-values-from-the-fields/m-p/526653#M88823</guid>
      <dc:creator>firefox95</dc:creator>
      <dc:date>2020-10-27T14:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to extract multivalue and null values from the fields.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-multivalue-and-null-values-from-the-fields/m-p/526664#M88824</link>
      <description>&lt;P&gt;You could modify your data to make extracting each field easier, then isolate the field you want further extraction on&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval events="Oct 19 16:55:17 xxxxx33 xxx_profiler 000324 1 0 2020-10-19 16:55:17:108 +01:00 000628 80002 INFO Profiler: Profiler Endpoint Profiling event occured, configversionid=xxxx, Endpointcertainitymetric=50, EndpointIPAddress=xx.xx.xx.xxx, EndpointProperty=dhcp-class-identifier=xx.xxx.com\\, Policyversion=000\\, AuthenticationIdentityStore=Internal Endpoints\\, lldpcachecapabilities=B\\;T\\, EndpointPolicyID=xxx-xxx-xxxxx\\, LogicalProfile=xxx-xxx-xx\\, xxx-xxxx-xxxx\\, AuthenticationMethod=lookup\\, FirstCollection=1518577\\, CacheUpdateTime=10000\\, IdentityAtoreGUID=\\, StaticAssignment=false\\, UserName=xxx\\, NmapScanCpunt=0\\, NetwrokDeviceName=xx.xx.xx.com\\, DestIPAddress=xx.xx.xxx.xx\\, AAA-Server=xxx\\, MessageCode=000\\, Device Type= Device Type#All Device Types\\,PortalUser=\\, AllowedProtocalMatchedRule=Wired_MM\\, ciaddre=x.x.x.x\\, BYODRegistration=Unknown\\, Calling-Station-ID=xx-xx-xx-xx\\, dhcp-requested-address=xx.xx.xx.xx\\, FailureReason=-\\, dhcp-parameter-request-list=1\\, XX\\, X\\, X\\, XX\\, XX\\, XX\\, XXX\\, PostureApplicable=Yes\\, Description=Voice:XXX Phones Caanry Waref #VLAN:IPT-VOICE#TYPE:VOICE#SYNC:1.0\\, phoneID=\\, hostname=xxxx\\, NAS-Port-Id=Gigabit Ethernet/x/xx\\, location=location #all locations#\\, uniquesubjectid=, EndpointSourceEvent=DNS Probe, EndpointIdentityGroup=xxx_Phones, ProfileServer=xx.xx.xx.xx,"
| rex field=events mode=sed "s/(?&amp;lt;k&amp;gt;[A-Za-z][A-Za-z\s_\-]+=)/@\1/g"
| rex field=events max_match=0 "@(?&amp;lt;keyvalue&amp;gt;[^@]+)"
| rex field=events mode=sed "s/@//g"&lt;/LI-CODE&gt;&lt;P&gt;I used&amp;nbsp;@ as it doesn't appear in your sample string but you may need to use something else depending on the rest of your data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 15:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-multivalue-and-null-values-from-the-fields/m-p/526664#M88824</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-27T15:16:17Z</dc:date>
    </item>
  </channel>
</rss>

