<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rex help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521432#M146941</link>
    <description>&lt;P&gt;Why rex and not spath again?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath input=rules ...&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 25 Sep 2020 11:15:39 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2020-09-25T11:15:39Z</dc:date>
    <item>
      <title>rex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521426#M146937</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;index=myindex| spath "Rules{}" output=rules |mvexpand rules&lt;BR /&gt;&amp;nbsp;| table device ip rules&lt;/P&gt;&lt;P&gt;Now my rules has data like below:&lt;/P&gt;&lt;P&gt;&lt;U&gt;rules&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{"name": "abc def - 123", "result": true}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i want to now make it into two columns rule_name and rule_result&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;can you please help me with the regex.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 10:15:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521426#M146937</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-09-25T10:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: rex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521428#M146939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\"name\":\s+\"(?&amp;lt;name&amp;gt;[^\"]+)\",\s+\"result\":\s+(?&amp;lt;result&amp;gt;\w+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/3DyKHn/1" target="_blank"&gt;https://regex101.com/r/3DyKHn/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 10:44:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521428#M146939</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-25T10:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: rex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521432#M146941</link>
      <description>&lt;P&gt;Why rex and not spath again?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath input=rules ...&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 25 Sep 2020 11:15:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521432#M146941</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-25T11:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: rex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521437#M146942</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 12:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521437#M146942</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-25T12:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: rex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521439#M146943</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;.. i am from a sabbatical vacation and also i havent used spath. so i miss some context here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;may i know how spath can do the job of rex?(this is what my understanding from ur reply)..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 12:08:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521439#M146943</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-09-25T12:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: rex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521443#M146945</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;spath is used for parsing and extracting fields from JSON and XML strings. In this instance, spath was used to extract the rules from _raw (which must have been JSON)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=myindex| spath "Rules{}" output=rules |mvexpand rules&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp; It yielded the next level down which appears to be more JSON&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"name": "abc def - 123", "result": true}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;So spath could have been used to extract these fields too&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath input=rules&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 25 Sep 2020 12:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-help/m-p/521443#M146945</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-25T12:23:09Z</dc:date>
    </item>
  </channel>
</rss>

