<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to fetch the same variable with different value from  the logs in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652466#M53579</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried below query:&lt;/P&gt;&lt;P&gt;index="600000304_d_gridgain_idx*" sourcetype=600000304_gg_abs_ipc2 "AssociationProcessor* associationStats={}] ---- controlFileData: ControlFileData" source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log"|rex " busDate=(?&amp;lt;busDate&amp;gt;),fileName=(?&amp;lt;fileName&amp;gt;),totalClosingBal=(?&amp;lt;totalClosingBal&amp;gt;)"&lt;BR /&gt;|table _time busDate fileName totalClosingBal&lt;BR /&gt;|sort _time&lt;/P&gt;&lt;P&gt;Getting below result:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="File.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26532iE7B74D5EB20405AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="File.PNG" alt="File.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is not the correct result&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the raw log&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;its capturing file name as "&lt;SPAN class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_MERGE" I WANT FILE NAME TO BE THE ONE PRESENT INSIDE&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;associationStats={} THAT IS "fileName=SETTLEMENT_TRANSFORM_ASSOCIATION"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2023-07-29&lt;/SPAN&gt; &lt;SPAN class=""&gt;10:39:52.949&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt; ] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Thread-3&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;AssociationProcessor&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;compareTransformStatsData&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;statisticData:&lt;/SPAN&gt; &lt;SPAN class=""&gt;StatisticData&lt;/SPAN&gt; [&lt;SPAN class=""&gt;selectedDataSet=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;rejectedDataSet=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalOutputRecords=19020051&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalInputRecords=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileSequenceNum=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileHeaderBusDt=null&lt;/SPAN&gt;, &lt;SPAN class=""&gt;busDt=07/28/2023&lt;/SPAN&gt;, &lt;STRONG&gt;&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_MERGE&lt;/SPAN&gt;&lt;/STRONG&gt;, &lt;SPAN class=""&gt;totalAchCurrOutstBalAmt=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalAchBalLastStmtAmt=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalClosingBal=7.100761644428E10&lt;/SPAN&gt;, &lt;SPAN class=""&gt;sourceName=null&lt;/SPAN&gt;, &lt;SPAN class=""&gt;version=1&lt;/SPAN&gt;, &lt;SPAN class=""&gt;associationStats=&lt;/SPAN&gt;{}] ---- &lt;SPAN class=""&gt;controlFileData:&lt;/SPAN&gt; &lt;SPAN class=""&gt;ControlFileData&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_ASSOCIATION&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;busDate=07/28/2023&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;fileSequenceNum=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalBalanceLastStmt=0.0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalCurrentOutstBal=0.0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalRecordsWritten=19020051&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalRecords=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalClosingBal=7.100761644428E10]&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Jul 2023 10:45:03 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2023-07-30T10:45:03Z</dc:date>
    <item>
      <title>How to fetch the same variable with different value from  the logs?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652455#M53570</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I am getting below raw logs:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;2023-07-29&lt;/SPAN&gt; &lt;SPAN class=""&gt;10:39:52.949&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt; ] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Thread-3&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt; &lt;SPAN class=""&gt;AssociationProcessor&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;compareTransformStatsData&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;statisticData:&lt;/SPAN&gt; &lt;SPAN class=""&gt;StatisticData&lt;/SPAN&gt; [&lt;SPAN class=""&gt;selectedDataSet=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;rejectedDataSet=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalOutputRecords=19020051&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalInputRecords=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileSequenceNum=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileHeaderBusDt=null&lt;/SPAN&gt;, &lt;SPAN class=""&gt;busDt=07/28/2023&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_MERGE&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalAchCurrOutstBalAmt=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalAchBalLastStmtAmt=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalClosingBal=7.100761644428E10&lt;/SPAN&gt;, &lt;SPAN class=""&gt;sourceName=null&lt;/SPAN&gt;, &lt;SPAN class=""&gt;version=1&lt;/SPAN&gt;, &lt;STRONG&gt;&lt;SPAN class=""&gt;associationStats=&lt;/SPAN&gt;{}] ---- &lt;SPAN class=""&gt;controlFileData:&lt;/SPAN&gt; &lt;SPAN class=""&gt;ControlFileData&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt; [&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_ASSOCIATION&lt;/SPAN&gt;, &lt;SPAN class=""&gt;busDate=07/28/2023&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileSequenceNum=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalBalanceLastStmt=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalCurrentOutstBal=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalRecordsWritten=19020051&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalRecords=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalClosingBal=7.100761644428E10]&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;I want to fetch the highlighted information the query I am trying is below:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;index="600000304_d_gridgain_idx*" sourcetype=600000304_gg_abs_ipc2 sourcetype = "600000304_gg_abs_ipc2" " &lt;STRONG&gt;AssociationProcessor*&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;associationStats={}] ---- controlFileData:ControlFileData&lt;/STRONG&gt;&lt;/SPAN&gt; " source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log" |rex " &lt;STRONG&gt;AssociationProcessor*&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;associationStats={}] ---- controlFileData:ControlFileData&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;busDt=(?&amp;lt;busDt&amp;gt;),fileName=(?&amp;lt;fileName&amp;gt;),totalClosingBal=(?&amp;lt;totalClosingBal&amp;gt;)"|table _time&amp;nbsp; busDt fileName totalClosingBal|sort _time&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;But I am getting this file name in my statistics "&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_MERGE"&amp;nbsp; rather I want the one inside Association Stats "&lt;STRONG&gt;SETTLEMENT_TRANSFORM_ASSOCIATION"&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Can someone gu&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 18:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652455#M53570</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-31T18:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652456#M53571</link>
      <description>&lt;P&gt;Try testing you regex in regex101.com to see what it is doing and hopefully figure out what needs to change.&lt;/P&gt;&lt;P&gt;I have made a start for you&amp;nbsp;&lt;A href="https://regex101.com/r/Uylo38/1" target="_blank"&gt;https://regex101.com/r/Uylo38/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hint: * means zero or more of the previous character (or match group) and [ is a special character in regex so would need to be escaped if you want to match with an actual [ in your string.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 09:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652456#M53571</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-30T09:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652457#M53572</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me here&amp;nbsp; I need to sow this panel tomorrow&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:00:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652457#M53572</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-30T10:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652459#M53574</link>
      <description>&lt;P&gt;Your regex statement is doing this:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;AssociationProcesso&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;matches the characters&amp;nbsp;AssociationProcesso&amp;nbsp;literally (case sensitive)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;r&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;matches the character&amp;nbsp;r&amp;nbsp;with index&amp;nbsp;11410&amp;nbsp;(7216&amp;nbsp;or&amp;nbsp;1628) literally (case sensitive)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;*&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;matches the previous token between&amp;nbsp;&lt;SPAN class=""&gt;zero&lt;/SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;SPAN class=""&gt;unlimited&lt;/SPAN&gt;&amp;nbsp;times,&amp;nbsp;as many times as possible, giving back as needed&amp;nbsp;&lt;SPAN class=""&gt;(greedy)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;associationStats={}]----controlFileData:ControlFileDatabusDt=&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;matches the characters&amp;nbsp;associationStats={}] ---- controlFileData:ControlFileData busDt=&amp;nbsp;literally (case sensitive)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Named Capture Group&amp;nbsp;busDt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;(?&amp;lt;busDt&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;— always finds a zero-length match&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;,fileName=&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;matches the characters&amp;nbsp;,fileName=&amp;nbsp;literally (case sensitive)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Named Capture Group&amp;nbsp;fileName&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;(?&amp;lt;fileName&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;— always finds a zero-length match&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;,totalClosingBal=&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;matches the characters&amp;nbsp;,totalClosingBal=&amp;nbsp;literally (case sensitive)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Named Capture Group&amp;nbsp;totalClosingBal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;(?&amp;lt;totalClosingBal&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;— always finds a zero-length match&lt;/DIV&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652459#M53574</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-30T10:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652460#M53575</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what regex I should use please guide&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index="600000304_d_gridgain_idx*" sourcetype=600000304_gg_abs_ipc2 sourcetype = "600000304_gg_abs_ipc2" " associationStats={}] ---- controlFileData: ControlFileData "&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log" |rex " associationStats={}] ---- controlFileData: ControlFileData "&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;busDt=(?&amp;lt;busDt&amp;gt;),fileName=(?&amp;lt;fileName&amp;gt;),totalClosingBal=(?&amp;lt;totalClosingBal&amp;gt;)"|table _time&amp;nbsp; busDt fileName totalClosingBal|sort _time&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But its taking the file other log also that is why I use AssociationProcessor*&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;please guide&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below is the screenshot I want to fetch first one&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture6.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26531i879A0D983EA48E93/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture6.PNG" alt="Capture6.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652460#M53575</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-30T10:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652462#M53576</link>
      <description>&lt;P&gt;You can still use&amp;nbsp;AssociationProcessor in your search filter, it doesn't have to also be in your regex&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="600000304_d_gridgain_idx*" sourcetype=600000304_gg_abs_ipc2 sourcetype = "600000304_gg_abs_ipc2" " AssociationProcessor* associationStats={}] ---- controlFileData:ControlFileData " source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log" 
|rex " busDt=(?&amp;lt;busDt&amp;gt;),fileName=(?&amp;lt;fileName&amp;gt;),totalClosingBal=(?&amp;lt;totalClosingBal&amp;gt;)"
|table _time  busDt fileName totalClosingBal
|sort _time&lt;/LI-CODE&gt;&lt;P&gt;Now you just need to fix the regex - for example, do the strings actually match up with your events? what characters are you tying to capture in the capture groups?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652462#M53576</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-30T10:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652463#M53577</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want filename BusDate and closing balance&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652463#M53577</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-30T10:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652464#M53578</link>
      <description>&lt;P&gt;What pattern would find those characters in the capture groups?&lt;/P&gt;&lt;P&gt;Try doing just the first one until you get that right, then move on to the next one - try this out in regex101.com as it tells you what your pattern is matching against.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:39:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652464#M53578</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-30T10:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652466#M53579</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried below query:&lt;/P&gt;&lt;P&gt;index="600000304_d_gridgain_idx*" sourcetype=600000304_gg_abs_ipc2 "AssociationProcessor* associationStats={}] ---- controlFileData: ControlFileData" source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log"|rex " busDate=(?&amp;lt;busDate&amp;gt;),fileName=(?&amp;lt;fileName&amp;gt;),totalClosingBal=(?&amp;lt;totalClosingBal&amp;gt;)"&lt;BR /&gt;|table _time busDate fileName totalClosingBal&lt;BR /&gt;|sort _time&lt;/P&gt;&lt;P&gt;Getting below result:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="File.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26532iE7B74D5EB20405AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="File.PNG" alt="File.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is not the correct result&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the raw log&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;its capturing file name as "&lt;SPAN class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_MERGE" I WANT FILE NAME TO BE THE ONE PRESENT INSIDE&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;associationStats={} THAT IS "fileName=SETTLEMENT_TRANSFORM_ASSOCIATION"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2023-07-29&lt;/SPAN&gt; &lt;SPAN class=""&gt;10:39:52.949&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt; ] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Thread-3&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;AssociationProcessor&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;compareTransformStatsData&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;statisticData:&lt;/SPAN&gt; &lt;SPAN class=""&gt;StatisticData&lt;/SPAN&gt; [&lt;SPAN class=""&gt;selectedDataSet=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;rejectedDataSet=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalOutputRecords=19020051&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalInputRecords=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileSequenceNum=0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;fileHeaderBusDt=null&lt;/SPAN&gt;, &lt;SPAN class=""&gt;busDt=07/28/2023&lt;/SPAN&gt;, &lt;STRONG&gt;&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_MERGE&lt;/SPAN&gt;&lt;/STRONG&gt;, &lt;SPAN class=""&gt;totalAchCurrOutstBalAmt=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalAchBalLastStmtAmt=0.0&lt;/SPAN&gt;, &lt;SPAN class=""&gt;totalClosingBal=7.100761644428E10&lt;/SPAN&gt;, &lt;SPAN class=""&gt;sourceName=null&lt;/SPAN&gt;, &lt;SPAN class=""&gt;version=1&lt;/SPAN&gt;, &lt;SPAN class=""&gt;associationStats=&lt;/SPAN&gt;{}] ---- &lt;SPAN class=""&gt;controlFileData:&lt;/SPAN&gt; &lt;SPAN class=""&gt;ControlFileData&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM_ASSOCIATION&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;busDate=07/28/2023&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;fileSequenceNum=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalBalanceLastStmt=0.0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalCurrentOutstBal=0.0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalRecordsWritten=19020051&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalRecords=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;totalClosingBal=7.100761644428E10]&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652466#M53579</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-30T10:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652468#M53581</link>
      <description>&lt;P&gt;Your rex is not capturing anything, you have not pattern inside you capture groups for rex to extract against. The value you are seeing for these fields is the value from the index search. You need to modify the rex so that it finds the right place in the log to start the extract from (this is called an anchor), then define what pattern you want to extract into the capture group / field. Look at what regex101.com is telling you is happening for your regex.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 10:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652468#M53581</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-30T10:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652469#M53582</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure exactly what rex need to be used here could you please guide&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 11:27:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652469#M53582</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-30T11:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652470#M53583</link>
      <description>&lt;P&gt;OK assuming you anchor to the right "fileName=", how would you describe the characters you want to be included in the fileName field?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 12:05:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652470#M53583</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-30T12:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652473#M53584</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below file name I want:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;fileName=SETTLEMENT_TRANSFORM&lt;/SPAN&gt;&lt;SPAN&gt;_&lt;/SPAN&gt;&lt;SPAN class=""&gt;ASSOCIATION&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;AssociationProcessor - compareTransformStatsData : statisticData: StatisticData [selectedDataSet=0, rejectedDataSet=0, totalOutputRecords=19020051, totalInputRecords=0, fileSequenceNum=0, fileHeaderBusDt=null, busDt=07/28/2023, fileName=SETTLEMENT_TRANSFORM_MERGE, totalAchCurrOutstBalAmt=0.0, totalAchBalLastStmtAmt=0.0, totalClosingBal=7.100761644428E10, sourceName=null, version=1, associationStats={}] ---- controlFileData: ControlFileData&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;STRONG&gt;fileName=SETTLEMENT_TRANSFORM_ASSOCIATION, busDate=07/28/2023, fileSequenceNum=0, totalBalanceLastStmt=0.0, totalCurrentOutstBal=0.0, totalRecordsWritten=19020051, totalRecords=0, totalClosingBal=7.100761644428E10&lt;/STRONG&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I want to display the information inside&amp;nbsp;&lt;SPAN class=""&gt;associationStats={}] ---- controlFileData: ControlFileData&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 15:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652473#M53584</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-30T15:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the same variable with different value from  the logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652476#M53585</link>
      <description>&lt;LI-CODE lang="markup"&gt;|rex "fileName=(?&amp;lt;fileName&amp;gt;SETTLEMENT_TRANSFORM_ASSOCIATION)"&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 30 Jul 2023 16:56:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-same-variable-with-different-value-from-the/m-p/652476#M53585</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-30T16:56:25Z</dc:date>
    </item>
  </channel>
</rss>

