<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to covert raw log to specific fields? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623174#M14552</link>
    <description>&lt;P&gt;Hello Champs..&lt;/P&gt;
&lt;P&gt;One of the splunk log is having below field&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Text:&lt;/SPAN&gt; &lt;SPAN class=""&gt;XCOM:&lt;/SPAN&gt; &lt;SPAN class=""&gt;File&lt;/SPAN&gt; &lt;SPAN class=""&gt;Receive&lt;/SPAN&gt; &lt;SPAN class=""&gt;ended&lt;/SPAN&gt; &lt;SPAN class=""&gt;REQ&lt;/SPAN&gt; &lt;SPAN class=""&gt;086094&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Remote&lt;/SPAN&gt; &lt;SPAN class=""&gt;LU&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.38.46.122&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;File&lt;/SPAN&gt; &lt;SPAN class=""&gt;$PRD10.C221130A&lt;/SPAN&gt; &lt;SPAN class=""&gt;Remotefile&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;/ABC/APP1/OUT/&lt;/SPAN&gt;C221130A&lt;/SPAN&gt; &lt;SPAN class=""&gt;63465&lt;/SPAN&gt; &lt;SPAN class=""&gt;bytes&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;578&lt;/SPAN&gt; &lt;SPAN class=""&gt;records&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;38875&lt;/SPAN&gt; &lt;SPAN class=""&gt;microsec&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I want to extract File_name = &lt;SPAN class=""&gt;$PRD10.C221130A&lt;/SPAN&gt; and Remote_file = &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;/ABC/APP1/OUT/&lt;/SPAN&gt;C221130A&lt;/SPAN&gt; and records = &lt;SPAN class=""&gt;578 from above Text filed. How this can be done? Please help&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 12:50:59 GMT</pubDate>
    <dc:creator>splunklearner99</dc:creator>
    <dc:date>2022-12-05T12:50:59Z</dc:date>
    <item>
      <title>How to covert raw log to specific fields?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623174#M14552</link>
      <description>&lt;P&gt;Hello Champs..&lt;/P&gt;
&lt;P&gt;One of the splunk log is having below field&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Text:&lt;/SPAN&gt; &lt;SPAN class=""&gt;XCOM:&lt;/SPAN&gt; &lt;SPAN class=""&gt;File&lt;/SPAN&gt; &lt;SPAN class=""&gt;Receive&lt;/SPAN&gt; &lt;SPAN class=""&gt;ended&lt;/SPAN&gt; &lt;SPAN class=""&gt;REQ&lt;/SPAN&gt; &lt;SPAN class=""&gt;086094&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Remote&lt;/SPAN&gt; &lt;SPAN class=""&gt;LU&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.38.46.122&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;File&lt;/SPAN&gt; &lt;SPAN class=""&gt;$PRD10.C221130A&lt;/SPAN&gt; &lt;SPAN class=""&gt;Remotefile&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;/ABC/APP1/OUT/&lt;/SPAN&gt;C221130A&lt;/SPAN&gt; &lt;SPAN class=""&gt;63465&lt;/SPAN&gt; &lt;SPAN class=""&gt;bytes&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;578&lt;/SPAN&gt; &lt;SPAN class=""&gt;records&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;38875&lt;/SPAN&gt; &lt;SPAN class=""&gt;microsec&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I want to extract File_name = &lt;SPAN class=""&gt;$PRD10.C221130A&lt;/SPAN&gt; and Remote_file = &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;/ABC/APP1/OUT/&lt;/SPAN&gt;C221130A&lt;/SPAN&gt; and records = &lt;SPAN class=""&gt;578 from above Text filed. How this can be done? Please help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 12:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623174#M14552</guid>
      <dc:creator>splunklearner99</dc:creator>
      <dc:date>2022-12-05T12:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to covert raw log to specific fields</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623193#M14553</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "File\s(?&amp;lt;File_name&amp;gt;\S+)\s*Remotefile\s(?&amp;lt;Remote_file&amp;gt;\S+).+(?&amp;lt;records&amp;gt;\d+)\srecords"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 05 Dec 2022 08:06:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623193#M14553</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-12-05T08:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to covert raw log to specific fields</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623219#M14556</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; , the query is giving below result&lt;/P&gt;&lt;P&gt;File_name = &lt;SPAN class=""&gt;$PRD10.C221130A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Remote_file = &lt;SPAN class=""&gt;/ABC/APP1/OUT/C221130A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;rerecords = 3&lt;/P&gt;&lt;P&gt;For records your query is taking the first byte of microsecond, expected 578 records&lt;/P&gt;&lt;P&gt;raw log: &lt;SPAN class=""&gt;File&lt;SPAN&gt; &lt;SPAN class=""&gt;$PRD10.C221130A&lt;SPAN&gt; &lt;SPAN class=""&gt;Remotefile&lt;SPAN&gt; &lt;SPAN class=""&gt;/ABC/APP1/OUT/C221130A&lt;SPAN&gt; &lt;SPAN class=""&gt;63465&lt;SPAN&gt; &lt;SPAN class=""&gt;bytes&lt;SPAN&gt;, &lt;SPAN class=""&gt;578&lt;SPAN&gt; &lt;SPAN class=""&gt;records&lt;SPAN&gt; &lt;SPAN class=""&gt;in&lt;SPAN&gt; &lt;SPAN class=""&gt;38875&lt;SPAN&gt; &lt;SPAN class=""&gt;microsec&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 12:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623219#M14556</guid>
      <dc:creator>splunklearner99</dc:creator>
      <dc:date>2022-12-05T12:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to covert raw log to specific fields</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623221#M14557</link>
      <description>&lt;P&gt;Try this - note the ? after the .+&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "File\s(?&amp;lt;File_name&amp;gt;\S+)\s*Remotefile\s(?&amp;lt;Remote_file&amp;gt;\S+).+?(?&amp;lt;records&amp;gt;\d+)\srecords"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 05 Dec 2022 12:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623221#M14557</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-12-05T12:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to covert raw log to specific fields</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623298#M14559</link>
      <description>&lt;P&gt;thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; , Similarly would be able to help for thisText: CBM042 CEDBatch finished, Chg=B221205D, Recs=2581, Errs=8&lt;/P&gt;&lt;P&gt;Where I need&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Status = CEDBatch finished&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Records = 2581&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Errors =9&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Change = B221205D&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 17:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623298#M14559</guid>
      <dc:creator>splunklearner99</dc:creator>
      <dc:date>2022-12-05T17:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to covert raw log to specific fields</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623299#M14560</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "\w+\s(?&amp;lt;status&amp;gt;[^,]+), Chg=(?&amp;lt;change&amp;gt;\w+), Recs=(?&amp;lt;records&amp;gt;\d+), Errs=(?&amp;lt;errors&amp;gt;\d+)"&lt;/LI-CODE&gt;&lt;P&gt;&lt;A href="https://regex101.com/r/nbhKPz/1" target="_self"&gt;https://regex101.com/r/nbhKPz/1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 17:57:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-covert-raw-log-to-specific-fields/m-p/623299#M14560</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-12-05T17:57:17Z</dc:date>
    </item>
  </channel>
</rss>

