<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field Extraction Struggle in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513741#M144174</link>
    <description>&lt;P&gt;i have these log entries, and I'm trying to extract the underlined data as "Business_Process"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1597246959262.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10219iB1AFB136C0CC3970/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_0-1597246959262.png" alt="sphiwee_0-1597246959262.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i'm using the below regex, on geg101 it extracts just fine but on splunk it exctracts a huge chunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;rex field=_raw "\Drun\.name\D:\D(?&amp;lt;Business_Process&amp;gt;.+)\D,\Drun.u"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i get below result in splunk&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_1-1597247468022.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10221iC28D67B7494F75D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_1-1597247468022.png" alt="sphiwee_1-1597247468022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Aug 2020 15:55:34 GMT</pubDate>
    <dc:creator>sphiwee</dc:creator>
    <dc:date>2020-08-12T15:55:34Z</dc:date>
    <item>
      <title>Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513741#M144174</link>
      <description>&lt;P&gt;i have these log entries, and I'm trying to extract the underlined data as "Business_Process"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1597246959262.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10219iB1AFB136C0CC3970/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_0-1597246959262.png" alt="sphiwee_0-1597246959262.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i'm using the below regex, on geg101 it extracts just fine but on splunk it exctracts a huge chunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;rex field=_raw "\Drun\.name\D:\D(?&amp;lt;Business_Process&amp;gt;.+)\D,\Drun.u"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i get below result in splunk&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_1-1597247468022.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10221iC28D67B7494F75D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_1-1597247468022.png" alt="sphiwee_1-1597247468022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 15:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513741#M144174</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-12T15:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513772#M144190</link>
      <description>Please share your sample data as text rather than a screen shot so people can test with it.</description>
      <pubDate>Wed, 12 Aug 2020 19:26:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513772#M144190</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-12T19:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513777#M144194</link>
      <description>&lt;P&gt;| rex “run\.name\”:\”(?&amp;lt;Business_Process&amp;gt;[^\”]+)”&lt;/P&gt;&lt;P&gt;don’t forget to replace double quotes from your keyboard. Double quotes may not match as I am typing from them my phone.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 19:34:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513777#M144194</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-12T19:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513813#M144205</link>
      <description>&lt;P&gt;wow thanks bro works perfectly, how can i learn to perfect my regex skills?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 22:01:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513813#M144205</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-12T22:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513820#M144206</link>
      <description>&lt;P&gt;having same issue, trying to extract red text&lt;BR /&gt;&lt;BR /&gt;"run\.author\.fullname\D:\"(?&amp;lt;USER&amp;gt;.+\"\,\"r)"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 17:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513820#M144206</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-15T17:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513832#M144208</link>
      <description>&lt;P&gt;&lt;SPAN&gt;just advice - don't post actual data here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;| rex “run\.author\.fullname\”:\”(?&amp;lt;User&amp;gt;[^\”]+)”&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 06:23:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/513832#M144208</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-13T06:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514246#M144334</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_1-1597512234006.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10273iBAB82CD461C46E16/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_1-1597512234006.png" alt="sphiwee_1-1597512234006.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hi thanks for the advice, seem to be getting an error on that regex&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 17:24:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514246#M144334</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-15T17:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514247#M144335</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "run\.author\.fullname\":\"(?&amp;lt;User&amp;gt;[^\"]+)"&lt;/LI-CODE&gt;&lt;P&gt;try now. the issue is with double quotes, as I had typed them from my phone.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 17:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514247#M144335</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-15T17:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514248#M144336</link>
      <description>&lt;P&gt;Yes I figured it was that, sorry to be bothersome.. any idea how can i vizualize a relationship between&amp;nbsp; Business_Process and User ? i want to show in a cool way which user ran which business process&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 17:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514248#M144336</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-08-15T17:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Struggle</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514261#M144337</link>
      <description>&lt;P&gt;| stats values(Business_process) as business_process by User&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 20:10:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-Struggle/m-p/514261#M144337</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-15T20:10:55Z</dc:date>
    </item>
  </channel>
</rss>

