<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help with regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352924#M104465</link>
    <description>&lt;P&gt;This helped,made some changes to it..Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2018 16:43:59 GMT</pubDate>
    <dc:creator>vrmandadi</dc:creator>
    <dc:date>2018-02-01T16:43:59Z</dc:date>
    <item>
      <title>help with regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352920#M104461</link>
      <description>&lt;P&gt;I have the below sample data, and I want to extract everything after the service URL till  &lt;CODE&gt;maxd=60&amp;amp;mind=60&lt;/CODE&gt; into a new field called &lt;CODE&gt;service&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;I have used (?i) url: (?P.+?)\w+= but it is not extracting completly&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;31 Jan 2018 20:22:13 [INFO ] AD Transaction: timestamp: 1513204259, transactionID: 2899739, reqID: 3022368026, uuid: 72dca744-b342-4aac-9861-005056b21335, type: ad request, transaction: start, service url: &lt;A href="http://mrm.mdc.time.com/ad/p/1?nw=376521&amp;amp;mode=live&amp;amp;vdur=600&amp;amp;flag=+sltp+amsl+ssus+amcb+dtrd&amp;amp;metr=1031&amp;amp;prof=376521:twc_hls_live&amp;amp;caid=SCI_LIVE&amp;amp;csid=stva_ios_tab_live&amp;amp;resp=vmap1&amp;amp;pvrn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vprn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vcid=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vcid2=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vip=24.211.233.182;;&amp;amp;ptgt=a&amp;amp;slau=midroll&amp;amp;slid=3545782&amp;amp;cpsq=1513204259&amp;amp;maxd=60&amp;amp;mind=60" target="test_blank"&gt;http://mrm.mdc.time.com/ad/p/1?nw=376521&amp;amp;mode=live&amp;amp;vdur=600&amp;amp;flag=+sltp+amsl+ssus+amcb+dtrd&amp;amp;metr=1031&amp;amp;prof=376521:twc_hls_live&amp;amp;caid=SCI_LIVE&amp;amp;csid=stva_ios_tab_live&amp;amp;resp=vmap1&amp;amp;pvrn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vprn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vcid=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vcid2=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vip=24.211.233.182;;&amp;amp;ptgt=a&amp;amp;slau=midroll&amp;amp;slid=3545782&amp;amp;cpsq=1513204259&amp;amp;maxd=60&amp;amp;mind=60&lt;/A&gt;, client url: &lt;A href="http://mmdai-linear-west-01.time.com" target="test_blank"&gt;http://mmdai-linear-west-01.time.com&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 31 Jan 2018 21:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352920#M104461</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2018-01-31T21:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: help with regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352921#M104462</link>
      <description>&lt;P&gt;How about trying this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your query to return events
| rex "service url:\s*(?&amp;lt;service&amp;gt;.*)&amp;amp;maxd=60&amp;amp;mind=60"
| table service
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;see extraction &lt;A href="https://regex101.com/r/2GK0SZ/2"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 21:13:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352921#M104462</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2018-01-31T21:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: help with regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352922#M104463</link>
      <description>&lt;P&gt;try this also:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...| rex "(?i)service url:\s*(?&amp;lt;service&amp;gt;.*)&amp;amp;maxd=60&amp;amp;mind=60" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Feb 2018 02:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352922#M104463</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-01T02:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: help with regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352923#M104464</link>
      <description>&lt;P&gt;hey try this run anywhere search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval _raw="31 Jan 2018 20:22:13 [INFO ] AD Transaction: timestamp: 1513204259, transactionID: 2899739, reqID: 3022368026, uuid: 72dca744-b342-4aac-9861-005056b21335, type: ad request, transaction: start, service url: &lt;A href="http://mrm.mdc.time.com/ad/p/1?nw=376521&amp;amp;mode=live&amp;amp;vdur=600&amp;amp;flag=+sltp+amsl+ssus+amcb+dtrd&amp;amp;metr=1031&amp;amp;prof=376521:twc_hls_live&amp;amp;caid=SCI_LIVE&amp;amp;csid=stva_ios_tab_live&amp;amp;resp=vmap1&amp;amp;pvrn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vprn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vcid=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vcid2=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vip=24.211.233.182;;&amp;amp;ptgt=a&amp;amp;slau=midroll&amp;amp;slid=3545782&amp;amp;cpsq=1513204259&amp;amp;maxd=60&amp;amp;mind=60" target="test_blank"&gt;http://mrm.mdc.time.com/ad/p/1?nw=376521&amp;amp;mode=live&amp;amp;vdur=600&amp;amp;flag=+sltp+amsl+ssus+amcb+dtrd&amp;amp;metr=1031&amp;amp;prof=376521:twc_hls_live&amp;amp;caid=SCI_LIVE&amp;amp;csid=stva_ios_tab_live&amp;amp;resp=vmap1&amp;amp;pvrn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vprn=72dca744-b342-4aac-9861-005056b21335&amp;amp;vcid=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vcid2=ff5cac5c-8dfe-31c5-a497-8bf8be88095a&amp;amp;vip=24.211.233.182;;&amp;amp;ptgt=a&amp;amp;slau=midroll&amp;amp;slid=3545782&amp;amp;cpsq=1513204259&amp;amp;maxd=60&amp;amp;mind=60&lt;/A&gt;, client url: &lt;A href="http://mmdai-linear-west-01.time.com&amp;quot;" target="test_blank"&gt;http://mmdai-linear-west-01.time.com"&lt;/A&gt;; 
| rex field=_raw "service\surl\:\s+(?&amp;lt;service_URL&amp;gt;.*)&amp;amp;maxd=60&amp;amp;mind=60"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In your environment, you should write&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;base_search&amp;gt; | rex field=_raw "service\surl\:\s+(?&amp;lt;service_URL&amp;gt;.*)&amp;amp;maxd=60&amp;amp;mind=60"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 06:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352923#M104464</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-02-01T06:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: help with regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352924#M104465</link>
      <description>&lt;P&gt;This helped,made some changes to it..Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 16:43:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-regex/m-p/352924#M104465</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2018-02-01T16:43:59Z</dc:date>
    </item>
  </channel>
</rss>

