<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in regular expression to extract data. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regular-expression-to-extract-data/m-p/472136#M132847</link>
    <description>&lt;P&gt;SPLUNKXML should be extracted automatically by splunk . If not use rex: | rex field=_raw "SPLUNKXML=(?.*), IPCODE"&lt;/P&gt;

&lt;P&gt;Sample query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults | eval _raw="2020-02-13 01:04:18.910, COUNT='863132', URL='http://122.32.10:8080/HP/Material', SAD='GET', SPLUNKXML='&amp;lt;APICALL&amp;gt;&amp;lt;IPCODE&amp;gt;201&amp;lt;/IPCODE&amp;gt;&amp;lt;returnTime&amp;gt;1581573606000&amp;lt;/returnTime&amp;gt;&amp;lt;data&amp;gt;&amp;lt;ULID&amp;gt;049726&amp;lt;/ULID&amp;gt;&amp;lt;requestId&amp;gt;$658262&amp;lt;/requestId&amp;gt;&amp;lt;currentStatus&amp;gt;SPlunk  - Picked&amp;lt;/currentStatus&amp;gt;&amp;lt;pickedQuantity&amp;gt;&amp;lt;value&amp;gt;634&amp;lt;/value&amp;gt;&amp;lt;uom&amp;gt;EA&amp;lt;/uom&amp;gt;&amp;lt;lastUpdateTime&amp;gt;1581399738000&amp;lt;/lastUpdateTime&amp;gt;&amp;lt;/data&amp;gt;&amp;lt;/APICALL&amp;gt;', IPCODE='111', Timestamp='2020-02-13 01:00:06.75'" | rex field=_raw "SPLUNKXML=(?&amp;lt;SPLUNKXML&amp;gt;.*), IPCODE"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 14 Feb 2020 10:20:30 GMT</pubDate>
    <dc:creator>manjunathmeti</dc:creator>
    <dc:date>2020-02-14T10:20:30Z</dc:date>
    <item>
      <title>Need help in regular expression to extract data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regular-expression-to-extract-data/m-p/472135#M132846</link>
      <description>&lt;P&gt;I need to filter the data from below _raw only the SPLUNKXML =""&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;_raw

2020-02-13 01:04:18.910, COUNT="863132", URL="http://122.32.10:8080/HP/Material", SAD="GET", SPLUNKXML="&amp;lt;APICALL&amp;gt;&amp;lt;IPCODE&amp;gt;201&amp;lt;/IPCODE&amp;gt;&amp;lt;returnTime&amp;gt;1581573606000&amp;lt;/returnTime&amp;gt;&amp;lt;data&amp;gt;&amp;lt;ULID&amp;gt;049726&amp;lt;/ULID&amp;gt;&amp;lt;requestId&amp;gt;$658262&amp;lt;/requestId&amp;gt;&amp;lt;currentStatus&amp;gt;SPlunk  - Picked&amp;lt;/currentStatus&amp;gt;&amp;lt;pickedQuantity&amp;gt;&amp;lt;value&amp;gt;634&amp;lt;/value&amp;gt;&amp;lt;uom&amp;gt;EA&amp;lt;/uom&amp;gt;&amp;lt;lastUpdateTime&amp;gt;1581399738000&amp;lt;/lastUpdateTime&amp;gt;&amp;lt;/data&amp;gt;&amp;lt;/APICALL&amp;gt;", IPCODE="111", Timestamp="2020-02-13 01:00:06.75"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OUtput needed: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    SPLUNKXML= "&amp;lt;APICALL&amp;gt;&amp;lt;IPCODE&amp;gt;201&amp;lt;/IPCODE&amp;gt;&amp;lt;returnTime&amp;gt;1581573606000&amp;lt;/returnTime&amp;gt;&amp;lt;data&amp;gt;&amp;lt;ULID&amp;gt;049726&amp;lt;/ULID&amp;gt;&amp;lt;requestId&amp;gt;$658262&amp;lt;/requestId&amp;gt;&amp;lt;currentStatus&amp;gt;SPlunk  - Picked&amp;lt;/currentStatus&amp;gt;&amp;lt;pickedQuantity&amp;gt;&amp;lt;value&amp;gt;634&amp;lt;/value&amp;gt;&amp;lt;uom&amp;gt;EA&amp;lt;/uom&amp;gt;&amp;lt;lastUpdateTime&amp;gt;1581399738000&amp;lt;/lastUpdateTime&amp;gt;&amp;lt;/data&amp;gt;&amp;lt;/APICALL&amp;gt;"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Feb 2020 09:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regular-expression-to-extract-data/m-p/472135#M132846</guid>
      <dc:creator>DataOrg</dc:creator>
      <dc:date>2020-02-14T09:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regular expression to extract data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regular-expression-to-extract-data/m-p/472136#M132847</link>
      <description>&lt;P&gt;SPLUNKXML should be extracted automatically by splunk . If not use rex: | rex field=_raw "SPLUNKXML=(?.*), IPCODE"&lt;/P&gt;

&lt;P&gt;Sample query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults | eval _raw="2020-02-13 01:04:18.910, COUNT='863132', URL='http://122.32.10:8080/HP/Material', SAD='GET', SPLUNKXML='&amp;lt;APICALL&amp;gt;&amp;lt;IPCODE&amp;gt;201&amp;lt;/IPCODE&amp;gt;&amp;lt;returnTime&amp;gt;1581573606000&amp;lt;/returnTime&amp;gt;&amp;lt;data&amp;gt;&amp;lt;ULID&amp;gt;049726&amp;lt;/ULID&amp;gt;&amp;lt;requestId&amp;gt;$658262&amp;lt;/requestId&amp;gt;&amp;lt;currentStatus&amp;gt;SPlunk  - Picked&amp;lt;/currentStatus&amp;gt;&amp;lt;pickedQuantity&amp;gt;&amp;lt;value&amp;gt;634&amp;lt;/value&amp;gt;&amp;lt;uom&amp;gt;EA&amp;lt;/uom&amp;gt;&amp;lt;lastUpdateTime&amp;gt;1581399738000&amp;lt;/lastUpdateTime&amp;gt;&amp;lt;/data&amp;gt;&amp;lt;/APICALL&amp;gt;', IPCODE='111', Timestamp='2020-02-13 01:00:06.75'" | rex field=_raw "SPLUNKXML=(?&amp;lt;SPLUNKXML&amp;gt;.*), IPCODE"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Feb 2020 10:20:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regular-expression-to-extract-data/m-p/472136#M132847</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-02-14T10:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regular expression to extract data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regular-expression-to-extract-data/m-p/472137#M132848</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval _raw="2020-02-13 01:04:18.910, COUNT='863132', URL='http://122.32.10:8080/HP/Material', SAD='GET', SPLUNKXML='&amp;lt;APICALL&amp;gt;&amp;lt;IPCODE&amp;gt;201&amp;lt;/IPCODE&amp;gt;&amp;lt;returnTime&amp;gt;1581573606000&amp;lt;/returnTime&amp;gt;&amp;lt;data&amp;gt;&amp;lt;ULID&amp;gt;049726&amp;lt;/ULID&amp;gt;&amp;lt;requestId&amp;gt;$658262&amp;lt;/requestId&amp;gt;&amp;lt;currentStatus&amp;gt;SPlunk  - Picked&amp;lt;/currentStatus&amp;gt;&amp;lt;pickedQuantity&amp;gt;&amp;lt;value&amp;gt;634&amp;lt;/value&amp;gt;&amp;lt;uom&amp;gt;EA&amp;lt;/uom&amp;gt;&amp;lt;lastUpdateTime&amp;gt;1581399738000&amp;lt;/lastUpdateTime&amp;gt;&amp;lt;/data&amp;gt;&amp;lt;/APICALL&amp;gt;', IPCODE='111', Timestamp='2020-02-13 01:00:06.75'" 
| kv
| foreach * [eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; = trim('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;', "\'")]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;@manjunathmeti  @premranjithj&lt;BR /&gt;
If you use &lt;CODE&gt;spath&lt;/CODE&gt; later, the query is here.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2020 00:58:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regular-expression-to-extract-data/m-p/472137#M132848</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-15T00:58:00Z</dc:date>
    </item>
  </channel>
</rss>

