<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: field extraction in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567163#M13021</link>
    <description>&lt;P&gt;Can you provide your search and an exact replica of your data. If that rex statement does not work in your environment, then the data you provided in your original post is not the same as the data in your search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 22:19:15 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2021-09-15T22:19:15Z</dc:date>
    <item>
      <title>field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567036#M13009</link>
      <description>&lt;P&gt;I have the following log&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;!!! --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;HUB&lt;/SPAN&gt; &lt;SPAN class="t"&gt;&lt;FONT color="#FF0000"&gt;ctxsdc1cvdi013.za.sbicdirectory.com&lt;/FONT&gt;:443&lt;/SPAN&gt; &lt;FONT color="#00FF00"&gt;&lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unavailable&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; !!! &lt;/SPAN&gt;&lt;SPAN class="t"&gt;user=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;molefe_user&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;password=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;FONT color="#0000FF"&gt;&lt;SPAN class="t"&gt;molefe&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;quota=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;user&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;host=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;002329bvpc123cw.branches.sbicdirectory.com&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;port=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;443&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;count=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;' !!! --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;HUB&lt;/SPAN&gt; &lt;SPAN class="t"&gt;002329bvpc123cw.branches.sbicdirectory.com:443&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unavailable&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; !!! &lt;/SPAN&gt;&lt;SPAN class="t"&gt;host=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t h"&gt;005558bvpc5ce4w.za.sbicdirectory&lt;/SPAN&gt;.com&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;port=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;443&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;count=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;' !!! --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;HUB&lt;/SPAN&gt; &lt;SPAN class="t"&gt;005558bvpc5ce4w.za.sbicdirectory.com:443&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unavailable&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; !!! &lt;/SPAN&gt;&lt;SPAN class="t"&gt;host=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;41360jnbpbb758w.za.sbicdirectory.com&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;port=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;443&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;count=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;' !!! --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;HUB&lt;/SPAN&gt; &lt;SPAN class="t"&gt;41360jnbpbb758w.za.sbicdirectory.com:443&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unavailable&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; !!! &lt;/SPAN&gt;&lt;SPAN class="t"&gt;host=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;48149jnbpbb041w.za.sbicdirectory.com&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;port=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;443&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;count=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;' !!! --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;HUB&lt;/SPAN&gt; &lt;SPAN class="t"&gt;48149jnbpbb041w.za.sbicdirectory.com:443&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unavailable&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; !!! &lt;/SPAN&gt;&lt;SPAN class="t"&gt;user=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;pips_lvl_one_user&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;password=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;pips_lvl_one&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;quota=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;user&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have above log and I'm struggling to extract the colored items&lt;BR /&gt;&lt;SPAN class="t"&gt;&lt;FONT color="#FF0000"&gt;ctxsdc1cvdi013.za.sbicdirectory.com = as workstation ID&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#00FF00"&gt;is unavailable = as&amp;nbsp; status&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;molefe = as quota&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 22:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567036#M13009</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2021-09-14T22:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567038#M13010</link>
      <description>&lt;P&gt;Run this search and check the rex statement&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="!!! --- HUB ctxsdc1cvdi013.za.sbicdirectory.com:443 is unavailable --- !!! user='molefe_user' password='molefe' quota='user' host='002329bvpc123cw.branches.sbicdirectory.com' port='443' count='1' !!! --- HUB 002329bvpc123cw.branches.sbicdirectory.com:443 is unavailable --- !!! host='005558bvpc5ce4w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 005558bvpc5ce4w.za.sbicdirectory.com:443 is unavailable --- !!! host='41360jnbpbb758w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 41360jnbpbb758w.za.sbicdirectory.com:443 is unavailable --- !!! host='48149jnbpbb041w.za.sbicdirectory.com' port='443' count='1' !!! --- HUB 48149jnbpbb041w.za.sbicdirectory.com:443 is unavailable --- !!! user='pips_lvl_one_user' password='pips_lvl_one' quota='user'"
| rex "!!! --- HUB (?&amp;lt;workstationId&amp;gt;[^:]*):\d+\s(?&amp;lt;status&amp;gt;[^-]*).*?password='(?&amp;lt;quota&amp;gt;[^']*)"&lt;/LI-CODE&gt;&lt;P&gt;However, did you want the password molefe to be the quota?&lt;/P&gt;&lt;P&gt;Also, this was posted as a single line log message and you only wanted those 3 fields - was that correct - the rex statement will get those.&lt;/P&gt;&lt;P&gt;However, it assumes the :port number will always be present. regex would need to change if that's not the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 22:49:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567038#M13010</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-09-14T22:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567062#M13012</link>
      <description>&lt;P&gt;Hi the port will always be the same, however when I run this regex command in my search it doesnt extract anything&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1631690245103.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15988i2E72EF8BF878DF9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_0-1631690245103.png" alt="sphiwee_0-1631690245103.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quota I think it was extracted automatically and its wrong hence I wanted the regex way&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 07:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567062#M13012</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2021-09-15T07:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567089#M13013</link>
      <description>&lt;P&gt;Can I also get the results of your search&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 09:28:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567089#M13013</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2021-09-15T09:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction</title>
      <link>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567163#M13021</link>
      <description>&lt;P&gt;Can you provide your search and an exact replica of your data. If that rex statement does not work in your environment, then the data you provided in your original post is not the same as the data in your search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 22:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/field-extraction/m-p/567163#M13021</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-09-15T22:19:15Z</dc:date>
    </item>
  </channel>
</rss>

