<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to build field in Other Usage</title>
    <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635944#M85</link>
    <description>&lt;P&gt;Hello thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;ok partially worked because&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the filed DESCRIPTION i just have Compliance Failure i shout have :&lt;/P&gt;&lt;P&gt;DESCRIPTION =&amp;nbsp;'&lt;SPAN class=""&gt;Port=23&lt;/SPAN&gt; &lt;SPAN class=""&gt;included&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;configuration&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;TN3270&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;as&lt;/SPAN&gt; &lt;SPAN class=""&gt;defined&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;Ports&lt;/SPAN&gt;, &lt;SPAN class=""&gt;Protocols&lt;/SPAN&gt;, &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;Services&lt;/SPAN&gt; &lt;SPAN class=""&gt;Management&lt;/SPAN&gt; (&lt;SPAN class=""&gt;PPSM&lt;/SPAN&gt;) &lt;SPAN class=""&gt;Category&lt;/SPAN&gt; &lt;SPAN class=""&gt;Assurance&lt;/SPAN&gt; &lt;SPAN class=""&gt;List&lt;/SPAN&gt; (&lt;SPAN class=""&gt;CAL&lt;/SPAN&gt;) &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;vulnerability&lt;/SPAN&gt; &lt;SPAN class=""&gt;assessments'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;can yu help me ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maurizio&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 15:50:37 GMT</pubDate>
    <dc:creator>mauriziotarducc</dc:creator>
    <dc:date>2023-03-24T15:50:37Z</dc:date>
    <item>
      <title>How to build fields?</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/633494#M81</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having log like :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;182&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Mar&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;18:18:24&lt;/SPAN&gt; &lt;SPAN class=""&gt;SND1&lt;/SPAN&gt; &lt;SPAN class=""&gt;Policy&lt;/SPAN&gt; &lt;SPAN class=""&gt;Manager&lt;/SPAN&gt; &lt;SPAN class=""&gt;severity=Info&lt;/SPAN&gt; &lt;SPAN class=""&gt;saf=1&lt;/SPAN&gt; &lt;SPAN class=""&gt;safd=RACF&lt;/SPAN&gt; &lt;SPAN class=""&gt;record=Mar&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;13:17:31&lt;/SPAN&gt; &lt;SPAN class=""&gt;SND1&lt;/SPAN&gt; &lt;SPAN class=""&gt;baspm&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;67174579&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Compliance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;='&lt;/SPAN&gt;&lt;SPAN class=""&gt;Sensitive&lt;/SPAN&gt; &lt;SPAN class=""&gt;Dataset=USS.SND2.VAR&lt;/SPAN&gt; &lt;SPAN class=""&gt;resides&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;z/OS&lt;/SPAN&gt; &lt;SPAN class=""&gt;shared&lt;/SPAN&gt; &lt;SPAN class=""&gt;DASD&lt;/SPAN&gt; &lt;SPAN class=""&gt;volume=SN2U01&lt;/SPAN&gt; &lt;SPAN class=""&gt;but&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;part&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;SPM&lt;/SPAN&gt; &lt;SPAN class=""&gt;dataset&lt;/SPAN&gt; &lt;SPAN class=""&gt;filter=SHRD&lt;/SPAN&gt;&lt;SPAN&gt;' [&lt;/SPAN&gt;&lt;SPAN class=""&gt;DS33795]&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;i would extract the fields :&lt;/P&gt;
&lt;P&gt;SND1 as LPAR&amp;nbsp; field&lt;/P&gt;
&lt;P&gt;[DS33795] ad DISANUM field&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;Sensitive&lt;/SPAN&gt; &lt;SPAN class=""&gt;Dataset=USS.SND2.VAR&lt;/SPAN&gt; &lt;SPAN class=""&gt;resides&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;z/OS&lt;/SPAN&gt; &lt;SPAN class=""&gt;shared&lt;/SPAN&gt; &lt;SPAN class=""&gt;DASD&lt;/SPAN&gt; &lt;SPAN class=""&gt;volume=SN2U01&lt;/SPAN&gt; &lt;SPAN class=""&gt;but&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;part&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;SPM&lt;/SPAN&gt; &lt;SPAN class=""&gt;dataset&lt;/SPAN&gt; &lt;SPAN class=""&gt;filter=SHRD&lt;/SPAN&gt;&lt;SPAN&gt;' as DESCRIPTION field&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you help me writing the regex ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;i started to write the following&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Compliance Failure" sourcetype="AMI SPM" | rex field=_raw "^(?:[^:\n]*:){2}\d+(?P&amp;lt;LPAR&amp;gt;\s+\w+)(?:[^\[\n]*\[){2}(?P&amp;lt;DISANUM&amp;gt;\w+)" offset_field=_extracted_fields_bounds | stats count by DISANUM&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;but i m not able to get the string after Compliance Failure&amp;nbsp; into the field DDESCRIPTION&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Maurizio&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 15:26:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/633494#M81</guid>
      <dc:creator>mauriziotarducc</dc:creator>
      <dc:date>2023-03-07T15:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to build fuild</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/633510#M82</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "^.*?(\d+:){2}\d+(?P&amp;lt;LPAR&amp;gt;\s+\w+).*Compliance Failure='(?&amp;lt;DESCRIPTION&amp;gt;[^']*)'\s+\[(?P&amp;lt;DISANUM&amp;gt;\w+)" offset_field=extracted_fields_bounds&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 23:39:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/633510#M82</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-03-06T23:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to build field</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635724#M83</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have another request :&lt;/P&gt;&lt;P&gt;i have the a text like (JSON Format)&amp;nbsp; :&amp;nbsp;&lt;/P&gt;&lt;P&gt;{"&lt;SPAN class=""&gt;Time&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt; "&lt;SPAN class=""&gt;2023-03-23T13:23:50.551&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;HostName&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt; "&lt;SPAN class=""&gt;SND1&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;Cat&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt; "&lt;SPAN class=""&gt;Policy&lt;/SPAN&gt; &lt;SPAN class=""&gt;Manager&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;Severity&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt; "&lt;SPAN class=""&gt;Info&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;SAF&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;SAFD&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt; "&lt;SPAN class=""&gt;RACF&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;Record&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt; "&lt;SPAN class=""&gt;Mar&lt;/SPAN&gt; &lt;SPAN class=""&gt;23&lt;/SPAN&gt; &lt;SPAN class=""&gt;09:23:49&lt;/SPAN&gt; &lt;SPAN class=""&gt;SND1&lt;/SPAN&gt; &lt;SPAN class=""&gt;baspm&lt;/SPAN&gt;[&lt;SPAN class=""&gt;33620189&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Compliance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failure=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;PASSWORD&lt;/SPAN&gt;(&lt;SPAN class=""&gt;INTERVAL&lt;/SPAN&gt;) &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;UserId=ZSX110&lt;/SPAN&gt; &lt;SPAN class=""&gt;should&lt;/SPAN&gt; &lt;SPAN class=""&gt;be&lt;/SPAN&gt; &lt;SPAN class=""&gt;60&lt;/SPAN&gt; &lt;SPAN class=""&gt;days.&lt;/SPAN&gt; &lt;SPAN class=""&gt;It&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;currently&lt;/SPAN&gt; &lt;SPAN class=""&gt;set&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;120&lt;/SPAN&gt;' [&lt;SPAN class=""&gt;DS223718&lt;/SPAN&gt;]&lt;/SPAN&gt;"}&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would like to have DESCRIPTION fileld based on "Complaince Failure" and DISANUM based on the content of [ and ]&amp;nbsp; character at the end of the string (in the above example the DISANUM is [DS223718] .&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maurizio&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 13:47:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635724#M83</guid>
      <dc:creator>mauriziotarducc</dc:creator>
      <dc:date>2023-03-23T13:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to build field</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635806#M84</link>
      <description>&lt;P&gt;In general, if it's a new question requiring a new answer, please ask it in a new question rather than using an already answered question, so others can help out&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your JSON is already auto extracted then do only the rex statement, otherwise use spath to extract the JSON from the raw event&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath
| rex field=Record "[^\]]*\]: (?&amp;lt;DESCRIPTION&amp;gt;[^=]*).*\[(?&amp;lt;DISANUM&amp;gt;\w+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 01:34:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635806#M84</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-03-24T01:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to build field</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635944#M85</link>
      <description>&lt;P&gt;Hello thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;ok partially worked because&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the filed DESCRIPTION i just have Compliance Failure i shout have :&lt;/P&gt;&lt;P&gt;DESCRIPTION =&amp;nbsp;'&lt;SPAN class=""&gt;Port=23&lt;/SPAN&gt; &lt;SPAN class=""&gt;included&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;configuration&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;TN3270&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;as&lt;/SPAN&gt; &lt;SPAN class=""&gt;defined&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;Ports&lt;/SPAN&gt;, &lt;SPAN class=""&gt;Protocols&lt;/SPAN&gt;, &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;Services&lt;/SPAN&gt; &lt;SPAN class=""&gt;Management&lt;/SPAN&gt; (&lt;SPAN class=""&gt;PPSM&lt;/SPAN&gt;) &lt;SPAN class=""&gt;Category&lt;/SPAN&gt; &lt;SPAN class=""&gt;Assurance&lt;/SPAN&gt; &lt;SPAN class=""&gt;List&lt;/SPAN&gt; (&lt;SPAN class=""&gt;CAL&lt;/SPAN&gt;) &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;vulnerability&lt;/SPAN&gt; &lt;SPAN class=""&gt;assessments'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;can yu help me ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maurizio&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635944#M85</guid>
      <dc:creator>mauriziotarducc</dc:creator>
      <dc:date>2023-03-24T15:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to build field</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635945#M86</link>
      <description>&lt;P&gt;or better based on the last example :&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;DESCRIPTION =&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;PASSWORD&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;INTERVAL&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;for&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;UserId=ZSX110&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;should&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;be&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;60&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;days.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;It&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;is&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;currently&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;set&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;120&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maurizio&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/635945#M86</guid>
      <dc:creator>mauriziotarducc</dc:creator>
      <dc:date>2023-03-24T15:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to build field</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636067#M87</link>
      <description>&lt;P&gt;Sorry - correct rex here&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=Record "[^\]]*\]:\s+Compliance Failure='(?&amp;lt;DESCRIPTION&amp;gt;[^']*).*\[(?&amp;lt;DISANUM&amp;gt;\w+)"&lt;/LI-CODE&gt;&lt;P&gt;It assumes the description is surrounded by single quote characters&lt;/P&gt;</description>
      <pubDate>Sun, 26 Mar 2023 22:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636067#M87</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-03-26T22:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to build fields?</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636102#M88</link>
      <description>&lt;P&gt;Hello good morning&amp;nbsp;&lt;/P&gt;&lt;P&gt;executing your new rex what i have is :&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN class=""&gt;23/03/23 13:23:52,425&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;{&lt;/SPAN&gt; &lt;A class="" href="http://localhost:8000/it-IT/app/search/search?q=search%20%22Compliance%20Failure%22%20%7C%20rex%20field%3DRecord%20%22%5B%5E%5C%5D%5D*%5C%5D%3A%5Cs%2BCompliance%20Failure%3D%27(%3F%3CDESCRIPTION%3E%5B%5E%27%5D*).*%5C%5B(%3F%3CDISANUM%3E%5Cw%2B)%22&amp;amp;display.page.search.mode=fast&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-7d%40w0&amp;amp;latest=%40w0&amp;amp;sid=1679902857.96#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt; &lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Cat&lt;/SPAN&gt;: &lt;SPAN class=""&gt;Policy Manager&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;HostName&lt;/SPAN&gt;: &lt;SPAN class=""&gt;SND1&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Record&lt;/SPAN&gt;: &lt;SPAN class=""&gt;Mar 23 09:23:52 SND1 baspm[33620189]: Compliance Failure='Port=23 included in configuration for TN3270 is not as defined in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments' [DS223821]&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;SAF&lt;/SPAN&gt;: &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;SAFD&lt;/SPAN&gt;: &lt;SPAN class=""&gt;RACF&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Severity&lt;/SPAN&gt;: &lt;SPAN class=""&gt;Info&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Time&lt;/SPAN&gt;: &lt;SPAN class=""&gt;2023-03-23T13:23:52.425&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But not Description and DISANUM .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maurizio&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 07:43:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636102#M88</guid>
      <dc:creator>mauriziotarducc</dc:creator>
      <dc:date>2023-03-27T07:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to build fields?</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636111#M89</link>
      <description>&lt;P&gt;Hello i did the following and now is ok&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Compliance Failure" | rex "Compliance Failure='(?&amp;lt;DESCRIPTION&amp;gt;[^']*)'\s*\[(?&amp;lt;DISANUM&amp;gt;[^\]]+)\]"&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Maurizio&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 08:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636111#M89</guid>
      <dc:creator>mauriziotarducc</dc:creator>
      <dc:date>2023-03-27T08:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to build fields?</title>
      <link>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636222#M90</link>
      <description>&lt;P&gt;If you have done spath and have a field following the spath called Record, then the rex should work, but if you don't have a field called Record because that field is not extracted, then it won't. Your rex is looking at the entire _raw field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 22:11:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/How-to-build-fields/m-p/636222#M90</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-03-27T22:11:12Z</dc:date>
    </item>
  </channel>
</rss>

