<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Regex in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683945#M9970</link>
    <description>&lt;P&gt;Below is the regex used, here we want to extract following fields:&lt;BR /&gt;DIM&lt;BR /&gt;TID&lt;BR /&gt;APPLICATION&lt;BR /&gt;POSITION&lt;BR /&gt;CORRLATIONID&lt;/P&gt;&lt;P&gt;The rex which i used is extraction DIM, TDI, APPLICATION as one field, but we need them separately.&lt;BR /&gt;We need to write the rex generic so that it should capture the data if there are different field names as well&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vishwa_0-1712855367398.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30368i7442291B89CD3253/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vishwa_0-1712855367398.png" alt="vishwa_0-1712855367398.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2024 17:15:22 GMT</pubDate>
    <dc:creator>vishwa</dc:creator>
    <dc:date>2024-04-11T17:15:22Z</dc:date>
    <item>
      <title>Custom Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683945#M9970</link>
      <description>&lt;P&gt;Below is the regex used, here we want to extract following fields:&lt;BR /&gt;DIM&lt;BR /&gt;TID&lt;BR /&gt;APPLICATION&lt;BR /&gt;POSITION&lt;BR /&gt;CORRLATIONID&lt;/P&gt;&lt;P&gt;The rex which i used is extraction DIM, TDI, APPLICATION as one field, but we need them separately.&lt;BR /&gt;We need to write the rex generic so that it should capture the data if there are different field names as well&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vishwa_0-1712855367398.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30368i7442291B89CD3253/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vishwa_0-1712855367398.png" alt="vishwa_0-1712855367398.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 17:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683945#M9970</guid>
      <dc:creator>vishwa</dc:creator>
      <dc:date>2024-04-11T17:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683949#M9971</link>
      <description>&lt;P&gt;You could try something like this&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ITWhisperer_0-1712856948472.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30370i3EDB2584259C6F7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ITWhisperer_0-1712856948472.png" alt="ITWhisperer_0-1712856948472.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 17:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683949#M9971</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-11T17:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683951#M9972</link>
      <description>&lt;P&gt;With this kind and quality of screenshot it's very hard to help.&lt;BR /&gt;Take a look to &lt;STRONG&gt;Fields&lt;/STRONG&gt; in settings and there especially for &lt;STRONG&gt;Field extractions&lt;/STRONG&gt; and &lt;STRONG&gt;Field transformations&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 17:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683951#M9972</guid>
      <dc:creator>SierraX</dc:creator>
      <dc:date>2024-04-11T17:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683952#M9973</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I need the generic rex like the way I posted in the screen shot because this is given in transforms.conf file and i tried the query u provided it's not working&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 17:52:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683952#M9973</guid>
      <dc:creator>vishwa</dc:creator>
      <dc:date>2024-04-11T17:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683994#M9974</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251452"&gt;@vishwa&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can use below regex;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;([A-Z]+)\:\s+(.+?)\s+&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 05:57:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/683994#M9974</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-04-12T05:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/684009#M9975</link>
      <description>&lt;P&gt;UGH. If you have any say in this - try to force the team responsible for producing these logs to get them in some reasonable format. It's some mix of pseudo-syslog embedded in some pseudo-json, and containing some "kinda delimited key/value pairs". It's not gonna end well.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 08:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Custom-Regex/m-p/684009#M9975</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-12T08:09:31Z</dc:date>
    </item>
  </channel>
</rss>

