<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic field extraction in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567139#M13014</link>
    <description>&lt;P&gt;| makeresults&lt;BR /&gt;&lt;BR /&gt;| eval _raw="!!! --- HUB ctxsdc1cvdi013.za.sbicdirectory.com:443 is unavailable --- !!! user='molefe_user' password='molefe' quota='user' host='002329bvpc123cw.branches.sbicdirectory.com' port='443' count='1' !!! --- HUB 002329bvpc123cw.branches.sbicdirectory.com:443 is unavailable --- !!! host='005558bvpc5ce4w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 005558bvpc5ce4w.za.sbicdirectory.com:443 is unavailable --- !!! host='41360jnbpbb758w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 41360jnbpbb758w.za.sbicdirectory.com:443 is unavailable --- !!! host='48149jnbpbb041w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 48149jnbpbb041w.za.sbicdirectory.com:443 is unavailable --- !!! user='pips_lvl_one_user' password='pips_lvl_one' quota='user'"&lt;BR /&gt;&lt;BR /&gt;| rex "!!! --- HUB (?[^:]*):\d+\s(?[^-]*).*?password='(?[^']*)"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running above rex command on splunk, it works when using it with "makeresults" command but when Im using it in my search it doesnt bring back any results&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 17:06:32 GMT</pubDate>
    <dc:creator>sphiwee</dc:creator>
    <dc:date>2021-09-15T17:06:32Z</dc:date>
    <item>
      <title>field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567139#M13014</link>
      <description>&lt;P&gt;| makeresults&lt;BR /&gt;&lt;BR /&gt;| eval _raw="!!! --- HUB ctxsdc1cvdi013.za.sbicdirectory.com:443 is unavailable --- !!! user='molefe_user' password='molefe' quota='user' host='002329bvpc123cw.branches.sbicdirectory.com' port='443' count='1' !!! --- HUB 002329bvpc123cw.branches.sbicdirectory.com:443 is unavailable --- !!! host='005558bvpc5ce4w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 005558bvpc5ce4w.za.sbicdirectory.com:443 is unavailable --- !!! host='41360jnbpbb758w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 41360jnbpbb758w.za.sbicdirectory.com:443 is unavailable --- !!! host='48149jnbpbb041w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 48149jnbpbb041w.za.sbicdirectory.com:443 is unavailable --- !!! user='pips_lvl_one_user' password='pips_lvl_one' quota='user'"&lt;BR /&gt;&lt;BR /&gt;| rex "!!! --- HUB (?[^:]*):\d+\s(?[^-]*).*?password='(?[^']*)"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running above rex command on splunk, it works when using it with "makeresults" command but when Im using it in my search it doesnt bring back any results&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 17:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567139#M13014</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2021-09-15T17:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567141#M13015</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;&amp;nbsp;what are you looking to extract here ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 17:26:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567141#M13015</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-15T17:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567143#M13016</link>
      <description>&lt;P&gt;&lt;SPAN&gt;!!! --- HUB &lt;FONT color="#FF0000"&gt;ctxsdc1cvdi013.za.sbicdirectory.com&lt;/FONT&gt;:443 is unavailable --- !!! user='&lt;FONT color="#FFCC00"&gt;molefe_user&lt;/FONT&gt;' password='molefe' quota='user' host='002329bvpc123cw.branches.sbicdirectory.com' port='443' count='1' !!! --- HUB 002329bvpc123cw.branches.sbicdirectory.com:443 &lt;FONT color="#3366FF"&gt;is unavailable&lt;/FONT&gt; --- !!! host='005558bvpc5ce4w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 005558bvpc5ce4w.za.sbicdirectory.com:443 is unavailable --- !!! host='41360jnbpbb758w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 41360jnbpbb758w.za.sbicdirectory.com:443 is unavailable --- !!! host='48149jnbpbb041w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 48149jnbpbb041w.za.sbicdirectory.com:443 is unavailable --- !!! user='pips_lvl_one_user' password='pips_lvl_one' quota='user'"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The text highlighted&amp;nbsp;red, first one as "&lt;FONT color="#FF0000"&gt;Workstation&lt;/FONT&gt;", second one as "&lt;FONT color="#FFCC00"&gt;Quota&lt;/FONT&gt;" , third one as "&lt;FONT color="#3366FF"&gt;status&lt;/FONT&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 17:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567143#M13016</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2021-09-15T17:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567149#M13017</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use below 3 lines in your search query and 3 new fields will be extracted:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| regex field=_raw "HUB\s(?P&amp;lt;Workstation&amp;gt;.*?)\:"
| regex field=_raw "user\=\'(?P&amp;lt;user&amp;gt;.*?)\'"
| regex field=_raw "443\s(?P&amp;lt;status&amp;gt;.*?)\-"&lt;/LI-CODE&gt;&lt;P&gt;Also, If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 18:37:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567149#M13017</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-15T18:37:45Z</dc:date>
    </item>
  </channel>
</rss>

