<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex Memory Issue in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Regex-Memory-Issue/m-p/558433#M38832</link>
    <description>&lt;P&gt;Sounds like you are trying to extract a multi-value field so you might try using max_match.&lt;/P&gt;&lt;P&gt;| rex field=file_content max_match=0 &amp;lt;expression&amp;gt;&lt;/P&gt;&lt;P&gt;Documentation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rex#2._Extract_from_multi-valued_fields_using_max_match" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rex#2._Extract_from_multi-valued_fields_using_max_match&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jul 2021 14:58:20 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2021-07-06T14:58:20Z</dc:date>
    <item>
      <title>Regex Memory Issue</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Regex-Memory-Issue/m-p/558407#M38831</link>
      <description>&lt;P&gt;I have a field that's called file_content on an source type.&lt;BR /&gt;This has a CSV inside.&lt;/P&gt;&lt;P&gt;Meaning every event has a field (file_content) that has a csv inside it. Every event is an email Can't be field extraction as the "file_content" is really hard to find inside the data.&lt;/P&gt;&lt;P&gt;I used the regex query to extract the data,&amp;nbsp;It's slow as I get 1 CSV per hour every day. so i wonder if there is any automation or a better way to do this?&lt;/P&gt;&lt;P&gt;My regex folows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=file_content "(?P&amp;lt;ContactId&amp;gt;[^\s,]*),(?P&amp;lt;Customernumber&amp;gt;[^\s,]*),(?P&amp;lt;AfterContactWorkDuration&amp;gt;[^\s,]*),(?P&amp;lt;AfterContactWorkEndTimestamp&amp;gt;[^,]*),(?P&amp;lt;AfterContactWorkStartTimestamp&amp;gt;[^,]*),(?P&amp;lt;AgentInteractionDuration&amp;gt;[^\s,]*),(?P&amp;lt;ConnectedToAgentTimestamp&amp;gt;[^,]*),(?P&amp;lt;CustomerHoldDuration&amp;gt;[^\s,]*),(?P&amp;lt;Hierarchygroups_Level1_GroupName&amp;gt;[^\s,]*),(?P&amp;lt;Hierarchygroups_Level2_GroupName&amp;gt;[^\s,]*),(?P&amp;lt;Hierarchygroups_Level3_GroupName&amp;gt;[^\s,]*),(?P&amp;lt;LongestHoldDuration&amp;gt;[^\s,]*),(?P&amp;lt;NumberOfHolds&amp;gt;[^\s,]*),(?P&amp;lt;Routingprofile&amp;gt;[^\s,]*),(?P&amp;lt;Agent&amp;gt;[^\s,]*),(?P&amp;lt;AgentConnectionAttempts&amp;gt;[^\s,]*),(?P&amp;lt;ConnectedToSystemTimestamp&amp;gt;[^,]*),(?P&amp;lt;DisconnectTimestamp&amp;gt;[^,]*),(?P&amp;lt;InitiationMethod&amp;gt;[^\s,]*),(?P&amp;lt;InitiationTimestamp&amp;gt;[^,]*),(?P&amp;lt;LastUpdateTimestamp&amp;gt;[^,]*),(?P&amp;lt;NextContactId&amp;gt;[^\s,]*),(?P&amp;lt;PreviousContactId&amp;gt;[^\s,]*),(?P&amp;lt;DequeueTimestamp&amp;gt;[^,]*),(?P&amp;lt;Duration&amp;gt;[^\s,]*),(?P&amp;lt;EnqueueTimestamp&amp;gt;[^,]*),(?P&amp;lt;Name&amp;gt;[^\s,]*),(?P&amp;lt;TransferCompletedTimestamp&amp;gt;[^,]*),(?P&amp;lt;HandleTime&amp;gt;[^\s,]*),(?P&amp;lt;TicketNumber&amp;gt;((\"[^\"]*\")+|[^\s,]*)),(?P&amp;lt;Account&amp;gt;[^\s,]*),(?P&amp;lt;AccountName&amp;gt;[^\s,]*),(?P&amp;lt;Country&amp;gt;[^\s,]*),(?P&amp;lt;Language&amp;gt;[^\s,]*),(?P&amp;lt;Site&amp;gt;[^\s,]*),(?P&amp;lt;WrapCode&amp;gt;[^\s,]*)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;And here is an example of how the data should look like (in csv):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ContactId,Customernumber,AfterContactWorkDuration,AfterContactWorkEndTimestamp,AfterContactWorkStartTimestamp,AgentInteractionDuration,ConnectedToAgentTimestamp,CustomerHoldDuration,Hierarchygroups_Level1_GroupName,Hierarchygroups_Level2_GroupName,Hierarchygroups_Level3_GroupName,LongestHoldDuration,NumberOfHolds,Routingprofile,Agent,AgentConnectionAttempts,ConnectedToSystemTimestamp,DisconnectTimestamp,InitiationMethod,InitiationTimestamp,LastUpdateTimestamp,NextContactId,PreviousContactId,DequeueTimestamp,Duration,EnqueueTimestamp,Name,TransferCompletedTimestamp,HandleTime,TicketNumber,Account,AccountName,Country,Language,Site,WrapCode
aaaa-xxxxxx,123456789,90,29/06/2021 01:00,29/06/2021 01:00,111,29/06/2021 01:00,0,country1,xx,yy,90,90,language,dummy,1,29/06/2021 01:00,29/06/2021 01:00,type_x,29/06/2021 01:00,29/06/2021 01:00,,,29/06/2021 01:00,11,29/06/2021 01:00,type_y,29/06/2021 01:00,201,A123,xxx,xxx,country_y,language,type_w,xxxx
bbbb-xxxxxx,987654321,90,29/06/2021 01:00,29/06/2021 01:00,111+P4,29/06/2021 01:00,0,country1,xx,yy,90,90,language,dummy,1,29/06/2021 01:00,29/06/2021 01:00,type_x,29/06/2021 01:00,29/06/2021 01:00,,,29/06/2021 01:00,11,29/06/2021 01:00,type_y,29/06/2021 01:00,201,"""A123,B123""",xxx,xxx,country_y,language,type_w,xxxx&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For example you can run a report everyday and save the outcome to an lookup , but this wouldn't work as it would be too much data for a lookup ,&amp;nbsp;I looked around and I found some people talk about summary index , do you think this would be a good option for me ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 13:35:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Regex-Memory-Issue/m-p/558407#M38831</guid>
      <dc:creator>Joannna</dc:creator>
      <dc:date>2021-07-06T13:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Memory Issue</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Regex-Memory-Issue/m-p/558433#M38832</link>
      <description>&lt;P&gt;Sounds like you are trying to extract a multi-value field so you might try using max_match.&lt;/P&gt;&lt;P&gt;| rex field=file_content max_match=0 &amp;lt;expression&amp;gt;&lt;/P&gt;&lt;P&gt;Documentation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rex#2._Extract_from_multi-valued_fields_using_max_match" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rex#2._Extract_from_multi-valued_fields_using_max_match&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 14:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Regex-Memory-Issue/m-p/558433#M38832</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2021-07-06T14:58:20Z</dc:date>
    </item>
  </channel>
</rss>

