<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extracting fields in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561770#M12827</link>
    <description>&lt;P&gt;Can you share the samples that's not working.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Aug 2021 03:59:41 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-08-03T03:59:41Z</dc:date>
    <item>
      <title>Extracting fields</title>
      <link>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561766#M12824</link>
      <description>&lt;P&gt;I have the following log&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2021-08-03T14:12:40&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;872&lt;/SPAN&gt; &lt;SPAN class="t"&gt;th=foo&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;cl=bla&lt;/SPAN&gt; &lt;SPAN class="t"&gt;p=INFO&lt;/SPAN&gt;&lt;SPAN&gt; {"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;tag&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;bla&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;goo&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;SPA&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;msg&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;dir&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;in&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;correlation&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2035456876870723587526&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;pack&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;ebcdic&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1234&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;001234&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;4&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;000000001234&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;6&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;000000001234&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;7&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0803141240&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;11&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;521464&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;41&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;51400055&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;FONT color="#008000"&gt;&lt;STRONG&gt;,"&lt;SPAN class="t"&gt;47&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;"&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN class="t"&gt;ERT0001234000&lt;FONT color="#008000"&gt;&lt;STRONG&gt;\\ARD&lt;/STRONG&gt;&lt;/FONT&gt;&lt;FONT color="#FF0000"&gt;ABAB&lt;/FONT&gt;&lt;FONT color="#FF00FF"&gt;DGDG&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;\\GRE1234\\VTE01123400824\\GDE00\\SSER\\Ort612348\\Ort072\\rtI0\\&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;49&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;124&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;61&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;12340000004&lt;/SPAN&gt;&lt;SPAN&gt;"}}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="inherit"&gt;I would like to extract the two &lt;/FONT&gt;fields&lt;FONT face="inherit"&gt;&amp;nbsp;in &lt;/FONT&gt;&lt;FONT color="#FF0000"&gt;RED&lt;/FONT&gt;&lt;FONT face="inherit"&gt; and &lt;/FONT&gt;&lt;FONT color="#FF00FF"&gt;Pink&amp;nbsp;&lt;FONT color="#000000"&gt;and rename field to Co&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="inherit"&gt;&lt;FONT color="#FF00FF"&gt;&lt;FONT color="#000000"&gt;The fields in &lt;STRONG&gt;&lt;FONT color="#008000"&gt;BOLD GREEN&lt;/FONT&gt;&amp;nbsp;&lt;/STRONG&gt;will be key and must be present, rest might or might not.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;This is what I got so far&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=bla&amp;nbsp; | rex \"47\":\"*ARD(?&amp;lt;CODA&amp;gt;.{4})&lt;/P&gt;&lt;P&gt;however this is not working and filed is not getting populated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 03:12:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561766#M12824</guid>
      <dc:creator>MicMoo</dc:creator>
      <dc:date>2021-08-03T03:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields</title>
      <link>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561767#M12825</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/130912"&gt;@MicMoo&lt;/a&gt;&amp;nbsp;Can you try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt; 
| rex "47\".+?\\\\ARD(?&amp;lt;red&amp;gt;\w{4})(?&amp;lt;pink&amp;gt;\w{4})"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 03 Aug 2021 03:22:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561767#M12825</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-03T03:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields</title>
      <link>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561768#M12826</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;, nearly there , when I use what you suggested nothing is extracted , however if I remove the "ARD" string ,&amp;nbsp; red and pink where populated but not all cases with the correct info&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 03:39:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561768#M12826</guid>
      <dc:creator>MicMoo</dc:creator>
      <dc:date>2021-08-03T03:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields</title>
      <link>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561770#M12827</link>
      <description>&lt;P&gt;Can you share the samples that's not working.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 03:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561770#M12827</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-03T03:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields</title>
      <link>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561771#M12828</link>
      <description>&lt;P&gt;Solved, should have simplified my search&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;\\\\ARD(?&amp;lt;RED&amp;gt;\w{4})(?&amp;lt;PINK&amp;gt;\w{4})&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 04:10:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Extracting-fields/m-p/561771#M12828</guid>
      <dc:creator>MicMoo</dc:creator>
      <dc:date>2021-08-03T04:10:34Z</dc:date>
    </item>
  </channel>
</rss>

