<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: While using If or Case , how to return the success value using Rex or Regex in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/While-using-If-or-Case-how-to-return-the-success-value-using-Rex/m-p/513301#M9447</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224769"&gt;@Nishant_Pandya&lt;/a&gt;&amp;nbsp;ideally if events are of different type, you should have different sourcetypes created and Regular Expression should be applied using props and transforms for Search Time field extraction.&lt;BR /&gt;&lt;BR /&gt;Please add sample (mock and anonymized) data from all sourcetypes for the community to assist you better. What is the field you want to extract and what is your RegEx?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2020 10:49:43 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2020-08-10T10:49:43Z</dc:date>
    <item>
      <title>While using If or Case , how to return the success value using Rex or Regex</title>
      <link>https://community.splunk.com/t5/Alerting/While-using-If-or-Case-how-to-return-the-success-value-using-Rex/m-p/513288#M9445</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;I get 4 types of logs in&amp;nbsp; different formats. If the log is from type 1, I want to use 1 regex. If the log is of type 2, I want to use another regex. And similarly for all 4 types of logs, I want to use 4 different regex and finally put all the types and Values returned by the regex in a table.&lt;/P&gt;&lt;P&gt;How can I do this?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 09:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/While-using-If-or-Case-how-to-return-the-success-value-using-Rex/m-p/513288#M9445</guid>
      <dc:creator>Nishant_Pandya</dc:creator>
      <dc:date>2020-08-10T09:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: While using If or Case , how to return the success value using Rex or Regex</title>
      <link>https://community.splunk.com/t5/Alerting/While-using-If-or-Case-how-to-return-the-success-value-using-Rex/m-p/513301#M9447</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224769"&gt;@Nishant_Pandya&lt;/a&gt;&amp;nbsp;ideally if events are of different type, you should have different sourcetypes created and Regular Expression should be applied using props and transforms for Search Time field extraction.&lt;BR /&gt;&lt;BR /&gt;Please add sample (mock and anonymized) data from all sourcetypes for the community to assist you better. What is the field you want to extract and what is your RegEx?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 10:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/While-using-If-or-Case-how-to-return-the-success-value-using-Rex/m-p/513301#M9447</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2020-08-10T10:49:43Z</dc:date>
    </item>
  </channel>
</rss>

