<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I make a field extraction that selects only the first occurrence? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422575#M121349</link>
    <description>&lt;P&gt;Thank you for your answer!&lt;BR /&gt;
When I test your regex then I see there are two match objects:&lt;BR /&gt;
&lt;A href="https://regex101.com/r/lQXqFx/1"&gt;https://regex101.com/r/lQXqFx/1&lt;/A&gt;&lt;BR /&gt;
How will Splunk behave in this case?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Dec 2018 07:41:30 GMT</pubDate>
    <dc:creator>whrg</dc:creator>
    <dc:date>2018-12-05T07:41:30Z</dc:date>
    <item>
      <title>How do I make a field extraction that selects only the first occurrence?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422573#M121347</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have events that span multiple lines. One such event looks as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...
# User details
ID: 123
Username: admin
Group: admin
Group: bin
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Each event has at least one &lt;EM&gt;Group&lt;/EM&gt; line.&lt;/P&gt;

&lt;P&gt;I want to create a field extraction for the first occurence of Group.&lt;/P&gt;

&lt;P&gt;So, for the example above the extracted field should have the value &lt;STRONG&gt;admin&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;How do I create such a field extraction?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 13:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422573#M121347</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2018-12-04T13:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I make a field extraction that selects only the first occurrence?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422574#M121348</link>
      <description>&lt;P&gt;Try this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex Group:\s(?&amp;lt;group&amp;gt;\w+)\n+
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:48:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422574#M121348</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-12-04T14:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do I make a field extraction that selects only the first occurrence?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422575#M121349</link>
      <description>&lt;P&gt;Thank you for your answer!&lt;BR /&gt;
When I test your regex then I see there are two match objects:&lt;BR /&gt;
&lt;A href="https://regex101.com/r/lQXqFx/1"&gt;https://regex101.com/r/lQXqFx/1&lt;/A&gt;&lt;BR /&gt;
How will Splunk behave in this case?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 07:41:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422575#M121349</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2018-12-05T07:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do I make a field extraction that selects only the first occurrence?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422576#M121350</link>
      <description>&lt;P&gt;try this in splunk with the rex command its working&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 09:32:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422576#M121350</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-12-05T09:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: How do I make a field extraction that selects only the first occurrence?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422577#M121351</link>
      <description>&lt;P&gt;It is working.&lt;BR /&gt;
However, I cannot find any documentation as to Splunk handles multiple match objects.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 11:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422577#M121351</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2018-12-05T11:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I make a field extraction that selects only the first occurrence?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422578#M121352</link>
      <description>&lt;P&gt;by default its matching ungreedy, and if you want it to be global you can add flaggs.&lt;/P&gt;

&lt;P&gt;I am not sure if there is any doc on that.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 12:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422578#M121352</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-12-05T12:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I make a field extraction that selects only the first occurrence?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422579#M121353</link>
      <description>&lt;P&gt;It's working off that &lt;CODE&gt;\n+&lt;/CODE&gt; added at the end, saying grab only the first match. If this answered your question, please accept it and close it out&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 14:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-make-a-field-extraction-that-selects-only-the-first/m-p/422579#M121353</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-12-05T14:51:19Z</dc:date>
    </item>
  </channel>
</rss>

