<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to extract filed from text File in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/How-to-extract-filed-from-text-File/m-p/398651#M8041</link>
    <description>&lt;P&gt;Hi All,&lt;BR /&gt;
I am reading text file from one of the server using UF, data in splunk  looks like -&lt;/P&gt;

&lt;P&gt;Total expected size 1042532502 MB&lt;BR /&gt;
 Name: (state)                                 Number of copies: Size:&lt;BR /&gt;&lt;BR /&gt;
SLP-MEDIUM-DDX1_CATALOG_2W (inactive)                        4      111676 MB&lt;BR /&gt;
SLP-MEDIUM-DDX1_MSDP_CATALOG_2W (inactive)                  17     1292279 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC2DXi_1M (inactive)                    514    81442047 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC2DXi_1M_&lt;EM&gt;DC1 (inactive)          4746   525210649 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC2DXi_1M&lt;/EM&gt;&lt;EM&gt;DC1 (inactive)            100    15054931 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_3M-DC2DXi_1Y (inactive)                     22     7815733 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_3M-DC2DXi_1Y&lt;/EM&gt;&lt;EM&gt;DC1 (inactive)              9     1419550 MB&lt;BR /&gt;
SLP-MEDIUM-DDX1_MSDP_CATALOG_2W (inactive)                   6          &amp;lt;1 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC1DXi_1M (inactive)                     74     8478513 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC1DXi_1M&lt;/EM&gt;&lt;EM&gt;DC2 (inactive)          1196   105875404 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC1DXi_1M&lt;/EM&gt;&lt;EM&gt;DC2 (inactive)            159    15961308 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_3M-DC1DXi_1Y&lt;/EM&gt;_DC2 (inactive)            50     3037526 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP2A_1M (active)                         1170    25512602 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP2A_5W (inactive)                        179     1939354 MB&lt;BR /&gt;
SLP-MEDIUM-DD_2W-DP2D_1M (active)                         3274    37605665 MB&lt;BR /&gt;
SLP-MEDIUM-DE_2W-DP2E_1M (active)                          990    90378841 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP1A_1M (active)                          816    20788679 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP1A_5W (inactive)                         56      168606 MB&lt;BR /&gt;
SLP-MEDIUM-DD_2W-DP1D_1M (active)                         2503    12663760 MB&lt;BR /&gt;
SLP-MEDIUM-DE_2W-DP1E_1M (active)                          816    87799167 MB&lt;/P&gt;

&lt;P&gt;I need to extract fields out of this data such as Total expected size, Name: (state) ,Number of copies,Size&lt;/P&gt;

&lt;P&gt;Any method to extract it out, please let me know ?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:23:43 GMT</pubDate>
    <dc:creator>shugup2923</dc:creator>
    <dc:date>2020-09-30T01:23:43Z</dc:date>
    <item>
      <title>How to extract filed from text File</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-extract-filed-from-text-File/m-p/398651#M8041</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;
I am reading text file from one of the server using UF, data in splunk  looks like -&lt;/P&gt;

&lt;P&gt;Total expected size 1042532502 MB&lt;BR /&gt;
 Name: (state)                                 Number of copies: Size:&lt;BR /&gt;&lt;BR /&gt;
SLP-MEDIUM-DDX1_CATALOG_2W (inactive)                        4      111676 MB&lt;BR /&gt;
SLP-MEDIUM-DDX1_MSDP_CATALOG_2W (inactive)                  17     1292279 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC2DXi_1M (inactive)                    514    81442047 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC2DXi_1M_&lt;EM&gt;DC1 (inactive)          4746   525210649 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC2DXi_1M&lt;/EM&gt;&lt;EM&gt;DC1 (inactive)            100    15054931 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_3M-DC2DXi_1Y (inactive)                     22     7815733 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_3M-DC2DXi_1Y&lt;/EM&gt;&lt;EM&gt;DC1 (inactive)              9     1419550 MB&lt;BR /&gt;
SLP-MEDIUM-DDX1_MSDP_CATALOG_2W (inactive)                   6          &amp;lt;1 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC1DXi_1M (inactive)                     74     8478513 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC1DXi_1M&lt;/EM&gt;&lt;EM&gt;DC2 (inactive)          1196   105875404 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_2W-DC1DXi_1M&lt;/EM&gt;&lt;EM&gt;DC2 (inactive)            159    15961308 MB&lt;BR /&gt;
SLP-MEDIUM-DDXi_3M-DC1DXi_1Y&lt;/EM&gt;_DC2 (inactive)            50     3037526 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP2A_1M (active)                         1170    25512602 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP2A_5W (inactive)                        179     1939354 MB&lt;BR /&gt;
SLP-MEDIUM-DD_2W-DP2D_1M (active)                         3274    37605665 MB&lt;BR /&gt;
SLP-MEDIUM-DE_2W-DP2E_1M (active)                          990    90378841 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP1A_1M (active)                          816    20788679 MB&lt;BR /&gt;
SLP-MEDIUM-DA_2W-DP1A_5W (inactive)                         56      168606 MB&lt;BR /&gt;
SLP-MEDIUM-DD_2W-DP1D_1M (active)                         2503    12663760 MB&lt;BR /&gt;
SLP-MEDIUM-DE_2W-DP1E_1M (active)                          816    87799167 MB&lt;/P&gt;

&lt;P&gt;I need to extract fields out of this data such as Total expected size, Name: (state) ,Number of copies,Size&lt;/P&gt;

&lt;P&gt;Any method to extract it out, please let me know ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:23:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-extract-filed-from-text-File/m-p/398651#M8041</guid>
      <dc:creator>shugup2923</dc:creator>
      <dc:date>2020-09-30T01:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract filed from text File</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-extract-filed-from-text-File/m-p/398652#M8042</link>
      <description>&lt;P&gt;hello there, &lt;BR /&gt;
you can use &lt;CODE&gt;| rex&lt;/CODE&gt; command as shown below, or use the field extractor, see link:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/ExtractfieldsinteractivelywithIFX"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/ExtractfieldsinteractivelywithIFX&lt;/A&gt;&lt;BR /&gt;
you might have some challenges with the &lt;CODE&gt;&amp;lt;1&lt;/CODE&gt; value that will need extra work, highlighted in the screenshot&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults count=1
| eval data = "SLP-MEDIUM-DDX1_CATALOG_2W (inactive) 4 111676 MB;;;SLP-MEDIUM-DDX1_MSDP_CATALOG_2W (inactive) 17 1292279 MB;;;SLP-MEDIUM-DDXi_2W-DC2DXi_1M (inactive) 514 81442047 MB;;;SLP-MEDIUM-DDXi_2W-DC2DXi_1M_DC1 (inactive) 4746 525210649 MB;;;SLP-MEDIUM-DDXi_2W-DC2DXi_1MDC1 (inactive) 100 15054931 MB;;;SLP-MEDIUM-DDXi_3M-DC2DXi_1Y (inactive) 22 7815733 MB;;;SLP-MEDIUM-DDXi_3M-DC2DXi_1YDC1 (inactive) 9 1419550 MB;;;SLP-MEDIUM-DDX1_MSDP_CATALOG_2W (inactive) 6 &amp;lt;1 MB;;;SLP-MEDIUM-DDXi_2W-DC1DXi_1M (inactive) 74 8478513 MB;;;SLP-MEDIUM-DDXi_2W-DC1DXi_1MDC2 (inactive) 1196 105875404 MB;;;SLP-MEDIUM-DDXi_2W-DC1DXi_1MDC2 (inactive) 159 15961308 MB;;;SLP-MEDIUM-DDXi_3M-DC1DXi_1Y_DC2 (inactive) 50 3037526 MB;;;SLP-MEDIUM-DA_2W-DP2A_1M (active) 1170 25512602 MB;;;SLP-MEDIUM-DA_2W-DP2A_5W (inactive) 179 1939354 MB;;;SLP-MEDIUM-DD_2W-DP2D_1M (active) 3274 37605665 MB;;;SLP-MEDIUM-DE_2W-DP2E_1M (active) 990 90378841 MB;;;SLP-MEDIUM-DA_2W-DP1A_1M (active) 816 20788679 MB;;;SLP-MEDIUM-DA_2W-DP1A_5W (inactive) 56 168606 MB;;;SLP-MEDIUM-DD_2W-DP1D_1M (active) 2503 12663760 MB;;;SLP-MEDIUM-DE_2W-DP1E_1M (active) 816 87799167 MB"
| makemv delim=";;;" data 
| mvexpand data
| rename COMMENT as "above generates sample data, below is your rex"
| rex field=data "(?&amp;lt;Name&amp;gt;[^\s]+)\s\((?&amp;lt;state&amp;gt;[^\)]+)\)\s(?&amp;lt;number_of_copies&amp;gt;[^\s]+)\s(?&amp;lt;size&amp;gt;[^\s]+)\s(?&amp;lt;size_unit&amp;gt;[^\s]+)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;screenshot:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7373iF51B288B7FB828F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 11:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-extract-filed-from-text-File/m-p/398652#M8042</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-07-17T11:16:48Z</dc:date>
    </item>
  </channel>
</rss>

