<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic field extraction after brackets value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/field-extraction-after-brackets-value/m-p/483017#M135263</link>
    <description>&lt;P&gt;hi i have log file like below&lt;BR /&gt;
need to extact the section after first "&lt;STRONG&gt;]&lt;/STRONG&gt;" to "&lt;STRONG&gt;[&lt;/STRONG&gt;" or "&lt;STRONG&gt;.&lt;/STRONG&gt;" or "&lt;STRONG&gt;:&lt;/STRONG&gt;"&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2020-04-24 23:59:59,511 INFO  ABCD.InIT-Service-1234567 [SrvListener] Receive Message[123456789ABCD123E123456789*] from [Service.APP]
2020-04-24 23:59:57,055 INFO  ABCD.InIT-Service-1234567_EFGH.InIT-AppService-5764693 [AbcEndpointManager] Send Message [123456789ABCD123456789123456789*] to A[000] B[0000]
2020-04-24 23:59:59,081 INFO  ABCD.InIT-Host-1234567_EFGH.InIT-Service-1234567 [TopologyProcessorService] Message Processed: A[000] B[0000]
2020-04-24 23:29:59,844 INFO  ABCD.InIT-Service-1234567 [NetworkProcessor] NetworkProcessor Accomplished: A[000] B[0000]
2020-04-24 23:29:59,851 INFO  NAME-1234567 [ExecuteService] CustomeService_clusterCustomeCommand chain was done. Define Parameters[input0='00000',input1='000000']
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;expected value:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Receive Message&lt;/LI&gt;
&lt;LI&gt;Send Message&lt;/LI&gt;
&lt;LI&gt;Message Processed&lt;/LI&gt;
&lt;LI&gt;NetworkProcessor Accomplished&lt;/LI&gt;
&lt;LI&gt;CustomeService_clusterCustomeCommand chain was done&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 25 Apr 2020 04:50:12 GMT</pubDate>
    <dc:creator>indeed_2000</dc:creator>
    <dc:date>2020-04-25T04:50:12Z</dc:date>
    <item>
      <title>field extraction after brackets value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/field-extraction-after-brackets-value/m-p/483017#M135263</link>
      <description>&lt;P&gt;hi i have log file like below&lt;BR /&gt;
need to extact the section after first "&lt;STRONG&gt;]&lt;/STRONG&gt;" to "&lt;STRONG&gt;[&lt;/STRONG&gt;" or "&lt;STRONG&gt;.&lt;/STRONG&gt;" or "&lt;STRONG&gt;:&lt;/STRONG&gt;"&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2020-04-24 23:59:59,511 INFO  ABCD.InIT-Service-1234567 [SrvListener] Receive Message[123456789ABCD123E123456789*] from [Service.APP]
2020-04-24 23:59:57,055 INFO  ABCD.InIT-Service-1234567_EFGH.InIT-AppService-5764693 [AbcEndpointManager] Send Message [123456789ABCD123456789123456789*] to A[000] B[0000]
2020-04-24 23:59:59,081 INFO  ABCD.InIT-Host-1234567_EFGH.InIT-Service-1234567 [TopologyProcessorService] Message Processed: A[000] B[0000]
2020-04-24 23:29:59,844 INFO  ABCD.InIT-Service-1234567 [NetworkProcessor] NetworkProcessor Accomplished: A[000] B[0000]
2020-04-24 23:29:59,851 INFO  NAME-1234567 [ExecuteService] CustomeService_clusterCustomeCommand chain was done. Define Parameters[input0='00000',input1='000000']
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;expected value:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Receive Message&lt;/LI&gt;
&lt;LI&gt;Send Message&lt;/LI&gt;
&lt;LI&gt;Message Processed&lt;/LI&gt;
&lt;LI&gt;NetworkProcessor Accomplished&lt;/LI&gt;
&lt;LI&gt;CustomeService_clusterCustomeCommand chain was done&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 04:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/field-extraction-after-brackets-value/m-p/483017#M135263</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2020-04-25T04:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction after brackets value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/field-extraction-after-brackets-value/m-p/483018#M135264</link>
      <description>&lt;P&gt;Use rex:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index = INDEX | rex "\]\s(?&amp;lt;message&amp;gt;[\w\s]+)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sample query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval _raw=" _raw
2020-04-24 23:59:59,511 INFO  ABCD.InIT-Service-1234567 [SrvListener] Receive Message[123456789ABCD123E123456789*] from [Service.APP]
2020-04-24 23:59:57,055 INFO  ABCD.InIT-Service-1234567_EFGH.InIT-AppService-5764693 [AbcEndpointManager] Send Message [123456789ABCD123456789123456789*] to A[000] B[0000]
2020-04-24 23:59:59,081 INFO  ABCD.InIT-Host-1234567_EFGH.InIT-Service-1234567 [TopologyProcessorService] Message Processed: A[000] B[0000]
2020-04-24 23:29:59,844 INFO  ABCD.InIT-Service-1234567 [NetworkProcessor] NetworkProcessor Accomplished: A[000] B[0000]
2020-04-24 23:29:59,851 INFO  NAME-1234567 [ExecuteService] CustomeService_clusterCustomeCommand chain was done. Define Parameters[input0='00000',input1='000000']" 
| multikv forceheader=1 
| rex "\]\s(?&amp;lt;message&amp;gt;[\w\s]+)" 
| fields _raw, message
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 25 Apr 2020 08:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/field-extraction-after-brackets-value/m-p/483018#M135264</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-04-25T08:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: field extraction after brackets value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/field-extraction-after-brackets-value/m-p/483019#M135265</link>
      <description>&lt;P&gt;work like charm, thank you &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 15:58:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/field-extraction-after-brackets-value/m-p/483019#M135265</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2020-04-25T15:58:03Z</dc:date>
    </item>
  </channel>
</rss>

