<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract data using regex? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401318#M116186</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206320"&gt;@493669&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;Sorry for inconvenience  caused. There are many data patterns are there. please find below for the sample.&lt;/P&gt;

&lt;P&gt;[15330442604] DATA SHOW: Enter;LUV-127lE$131.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15330744495] DATA Thing: SVR~1232.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;cup_used;&lt;BR /&gt;
[15380142481] DATA SHOW: En;cup_used;&lt;BR /&gt;
[15330442604] DATA SHOW: Enter;LUV-127lE$131.CBE.data.com;datat;Splunk;&lt;BR /&gt;
[15330744495] DATA Thing: SVR~1232.CBE.data.com En;min;max;splunk1&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;working;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;cup_used;&lt;BR /&gt;
[15380142481] DATA SHOW: En;cup_used;&lt;/P&gt;

&lt;P&gt;needed values : cup_used,CUP_Used,Splunk,splunk1,working.&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 21:27:08 GMT</pubDate>
    <dc:creator>Shan</dc:creator>
    <dc:date>2020-09-29T21:27:08Z</dc:date>
    <item>
      <title>How to extract data using regex?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401316#M116184</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I Have data in below mentioned format.&lt;BR /&gt;
I need to extract value &lt;CODE&gt;CUP_Used&lt;/CODE&gt; and &lt;CODE&gt;cup_used&lt;/CODE&gt; using regex and store it as a separate filed.&lt;BR /&gt;
But in below mentioned pattern &lt;CODE&gt;CUP_Used&lt;/CODE&gt; and &lt;CODE&gt;cup_used&lt;/CODE&gt; is available in 2nd or 3rd place in unstructured data set. I need to extract only &lt;CODE&gt;CUP_Used&lt;/CODE&gt; and &lt;CODE&gt;cup_used&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;[15330442604] DATA SHOW: Enter;LUV-127lE$131.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15330744495] DATA Thing: SVR~1232.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;cup_used;&lt;BR /&gt;
[15380142481] DATA SHOW: En;cup_used;&lt;/P&gt;

&lt;P&gt;I have used the below mentioned rex to extract &lt;CODE&gt;CUP_Used&lt;/CODE&gt; and &lt;CODE&gt;cup_used&lt;/CODE&gt;. But I'm getting values as mentioned below. But i don't need values like  s,LUV etc . With single rex i need to extract the value &lt;CODE&gt;CUP_Used&lt;/CODE&gt; and &lt;CODE&gt;cup_used&lt;/CODE&gt;.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LUV
CUP_Used
s
s
cup_used

\d\d\]\s[^:]+:\s[^;]+;(?P&amp;lt;hard&amp;gt;[a-zA-Z_]+)

\d\d\]\s[^:]+:\s[^;]+;(?P&amp;lt;hard&amp;gt;[^;]+);
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks in advance..&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401316#M116184</guid>
      <dc:creator>Shan</dc:creator>
      <dc:date>2020-09-29T21:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data using regex?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401317#M116185</link>
      <description>&lt;P&gt;try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...|rex "(?P&amp;lt;hard&amp;gt;\w+);$"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Sep 2018 05:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401317#M116185</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-09-27T05:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data using regex?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401318#M116186</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206320"&gt;@493669&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;Sorry for inconvenience  caused. There are many data patterns are there. please find below for the sample.&lt;/P&gt;

&lt;P&gt;[15330442604] DATA SHOW: Enter;LUV-127lE$131.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15330744495] DATA Thing: SVR~1232.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;CUP_Used;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;cup_used;&lt;BR /&gt;
[15380142481] DATA SHOW: En;cup_used;&lt;BR /&gt;
[15330442604] DATA SHOW: Enter;LUV-127lE$131.CBE.data.com;datat;Splunk;&lt;BR /&gt;
[15330744495] DATA Thing: SVR~1232.CBE.data.com En;min;max;splunk1&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;working;&lt;BR /&gt;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;cup_used;&lt;BR /&gt;
[15380142481] DATA SHOW: En;cup_used;&lt;/P&gt;

&lt;P&gt;needed values : cup_used,CUP_Used,Splunk,splunk1,working.&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:27:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401318#M116186</guid>
      <dc:creator>Shan</dc:creator>
      <dc:date>2020-09-29T21:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data using regex?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401319#M116187</link>
      <description>&lt;P&gt;updated the answer ..please try above&lt;BR /&gt;
this answer work if every line is one separate event&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 06:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401319#M116187</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-09-27T06:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data using regex?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401320#M116188</link>
      <description>&lt;P&gt;@493669,&lt;/P&gt;

&lt;P&gt;No its  not working..&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[15330442604] DATA SHOW: Enter;LUV-127lE$131.CBE.data.com;CUP_Used;
[15330744495] DATA Thing: SVR~1232.CBE.data.com;CUP_Used;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;CUP_Used;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;cup_used;
[15380142481] DATA SHOW: En;cup_used;
[15330442604] DATA SHOW: Enter;LUV-127lE$131.CBE.data.com;datat;Splunk;
[15330744495] DATA Thing: SVR~1232.CBE.data.com En;min;max;splunk1
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;working;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;cup_used;
[15380142481] DATA SHOW: En;cup_used;Retre;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;working;data;
[15380142481] DATA SHOW: Enter@FFDDEEF;s99vNN147.CBE.data.com;working;data;sdhgfsd;dshhd
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Sep 2018 08:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401320#M116188</guid>
      <dc:creator>Shan</dc:creator>
      <dc:date>2018-09-27T08:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data using regex?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401321#M116189</link>
      <description>&lt;P&gt;You keep coming up with new sample patterns. You'll really need to come up with a clear definition of what you want to extract, in order for anyone to come up with a working regex.&lt;/P&gt;

&lt;P&gt;For starters: please be more clear than "its not working". What results do you get and which of those are correct and which are not?&lt;/P&gt;

&lt;P&gt;From your earlier explanations, it seemed as if you want to capture the last 'field' in the line, but apparently that is not entirely the case? If you just want to check for the presence of one of those words you now mentioned (cup_used,CUP_Used,Splunk,splunk1,working), then try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "(?&amp;lt;hard&amp;gt;cup_used|CUP_Used|Splunk|splunk1|working)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://regex101.com/r/tFmL38/1" target="_blank"&gt;https://regex101.com/r/tFmL38/1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-using-regex/m-p/401321#M116189</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2020-09-29T21:27:10Z</dc:date>
    </item>
  </channel>
</rss>

