<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using regex to extract multiple values between tags in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-to-extract-multiple-values-between-tags/m-p/532363#M150386</link>
    <description>&lt;P&gt;The event contains a 'before' and 'after' list of permissions and users SIDs, I can get splunk to extract the entire 'before' list and the entire 'after' list but only as single events.&lt;/P&gt;&lt;P&gt;but i need to break it down to list&amp;nbsp; to indivudal Permission and SID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This it the entire event:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2020-12-07&lt;/SPAN&gt; &lt;SPAN class="t"&gt;22:45:51.123&lt;/SPAN&gt; &lt;SPAN class="t"&gt;91046&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SUCCESS&lt;/SPAN&gt;&amp;nbsp;Domain\User&amp;nbsp;&lt;SPAN class="t"&gt;Archive&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Permissions&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Archive&lt;/SPAN&gt; &lt;SPAN class="t"&gt;133481FD9531D0347BBCE92FFF45B4FE11110000evaultcol&lt;/SPAN&gt;&lt;SPAN&gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Archive&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ArchiveID=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;133481FD9531D0347vaultcol&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ArchiveName=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Last&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;First&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;OldManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCDCLCSWRPWPDT&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-10875&lt;/SPAN&gt;&lt;SPAN&gt;)(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCSW&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-2406856&lt;/SPAN&gt;&lt;SPAN&gt;)(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCSW&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-2406857&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/OldManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;NewManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;A&lt;SPAN&gt;;;&lt;/SPAN&gt;CCDCLCSWRPWPDT&lt;SPAN&gt;;;;&lt;/SPAN&gt;S-1-5-21-299502267-1960408961-839522115-10875&lt;SPAN&gt;)(&lt;/SPAN&gt;A&lt;SPAN&gt;;;&lt;/SPAN&gt;CCSW&lt;SPAN&gt;;;;&lt;/SPAN&gt;S-1-5-21-299502267-1960408961-839522115-2406856&lt;SPAN&gt;)(&lt;/SPAN&gt;A&lt;SPAN&gt;;;&lt;/SPAN&gt;CCSW&lt;SPAN&gt;;;;&lt;/SPAN&gt;S-1-5-21-299502267-1960408961-839522115-2406857&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCDCSWRPDT&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-3949157&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/NewManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Archive&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; ServerName&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;The 'before' list is between the&amp;nbsp;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;OldManualSD&lt;SPAN&gt;&amp;gt; and&amp;nbsp;&amp;lt;\OldManualSD&amp;gt; tags, the 'after' list is between the&amp;nbsp;&amp;lt;NewManualSD&amp;gt; and&amp;nbsp;&amp;lt;/NewManualSD&amp;gt; tags&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;The Permissions field is between the ;; and ;;; delimiters and is followed by the SID. There is a varying number of permsissons/SIDs in each event&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;Can get part way there; ex_OldManual_GP and ex_NewManual_GP fields extract from the "Info" field and the contain the before and after, but trying to get a second extraction based off&amp;nbsp;ex_OldManual_GP and ex_NewManual_GP always fails&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;from the event above, I would like:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;OldManual = A;;CCDCLCSWRPWPDT;;;S-1-5-21-299502367-1960408961-839522117-10475&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;OldManual = A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406456&lt;BR /&gt;OldManual = A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406457&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;NewManual =&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;A;;CCDCLCSWRPWPDT;;;S-1-5-21-299502367-1960408961-839522117-10875&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;NewManual = A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406456&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;NewManual =&amp;nbsp;&lt;/SPAN&gt;A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406457&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;NewManua l= A;;CCDCSWRPDT;;;S-1-5-21-299502367-1960408961-839522117-3949147&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;my transforms.conf file:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ex_fields_extract]&lt;BR /&gt;FIELDS = "AuditDate","AuditID","Status","UserName","CategoryName","SubCategoryName","ObjectID","Vault","info","MachineName"&lt;BR /&gt;DELIMS = "\t"&lt;/P&gt;&lt;P&gt;[ex_OldManual_GP]&lt;BR /&gt;SOURCE_KEY = info&lt;BR /&gt;REGEX=\&amp;gt;(&amp;lt;OldManualSD&amp;gt;D:)((?P&amp;lt;OldManual_GP&amp;gt;.*))(&amp;lt;\/OldManualSD&amp;gt;)&lt;/P&gt;&lt;P&gt;[ex_NewManual_GP]&lt;BR /&gt;SOURCE_KEY = info&lt;BR /&gt;REGEX=\&amp;gt;(&amp;lt;NewManualSD&amp;gt;D:)((?P&amp;lt;NewManual_GP&amp;gt;.*))(&amp;lt;\/NewManualSD&amp;gt;)&lt;/P&gt;&lt;P&gt;[ex_OldManual_MV]&lt;BR /&gt;SOURCE_KEY = OldManual_GP&lt;BR /&gt;REGEX=;;(?P&amp;lt;perm&amp;gt;\w+);;;*&lt;BR /&gt;MV_ADD=true&lt;/P&gt;&lt;P&gt;[ex_NewManual_MV]&lt;BR /&gt;SOURCE_KEY = NewManual_GP&lt;BR /&gt;REGEX=(?&amp;lt;NewManual&amp;gt;[^,]+),*&lt;BR /&gt;MV_ADD=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my props.conf file&lt;/P&gt;&lt;P&gt;[exlogs]&lt;BR /&gt;REPORT-ex_fields = ex_fields_extract&lt;BR /&gt;REPORT-mvalue = ex_OldManual_MV, ex_NewManual_MV, ex_NewManual_GP, ex_OldManual_GP&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2020 17:41:07 GMT</pubDate>
    <dc:creator>capilarity</dc:creator>
    <dc:date>2020-12-08T17:41:07Z</dc:date>
    <item>
      <title>Using regex to extract multiple values between tags</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-to-extract-multiple-values-between-tags/m-p/532363#M150386</link>
      <description>&lt;P&gt;The event contains a 'before' and 'after' list of permissions and users SIDs, I can get splunk to extract the entire 'before' list and the entire 'after' list but only as single events.&lt;/P&gt;&lt;P&gt;but i need to break it down to list&amp;nbsp; to indivudal Permission and SID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This it the entire event:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2020-12-07&lt;/SPAN&gt; &lt;SPAN class="t"&gt;22:45:51.123&lt;/SPAN&gt; &lt;SPAN class="t"&gt;91046&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SUCCESS&lt;/SPAN&gt;&amp;nbsp;Domain\User&amp;nbsp;&lt;SPAN class="t"&gt;Archive&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Permissions&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Archive&lt;/SPAN&gt; &lt;SPAN class="t"&gt;133481FD9531D0347BBCE92FFF45B4FE11110000evaultcol&lt;/SPAN&gt;&lt;SPAN&gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Archive&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ArchiveID=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;133481FD9531D0347vaultcol&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ArchiveName=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Last&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;First&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;OldManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCDCLCSWRPWPDT&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-10875&lt;/SPAN&gt;&lt;SPAN&gt;)(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCSW&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-2406856&lt;/SPAN&gt;&lt;SPAN&gt;)(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCSW&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-2406857&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/OldManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;NewManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;A&lt;SPAN&gt;;;&lt;/SPAN&gt;CCDCLCSWRPWPDT&lt;SPAN&gt;;;;&lt;/SPAN&gt;S-1-5-21-299502267-1960408961-839522115-10875&lt;SPAN&gt;)(&lt;/SPAN&gt;A&lt;SPAN&gt;;;&lt;/SPAN&gt;CCSW&lt;SPAN&gt;;;;&lt;/SPAN&gt;S-1-5-21-299502267-1960408961-839522115-2406856&lt;SPAN&gt;)(&lt;/SPAN&gt;A&lt;SPAN&gt;;;&lt;/SPAN&gt;CCSW&lt;SPAN&gt;;;;&lt;/SPAN&gt;S-1-5-21-299502267-1960408961-839522115-2406857&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;A&lt;/SPAN&gt;&lt;SPAN&gt;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CCDCSWRPDT&lt;/SPAN&gt;&lt;SPAN&gt;;;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;S-1-5-21-299502267-1960408961-839522115-3949157&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/NewManualSD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Archive&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; ServerName&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;The 'before' list is between the&amp;nbsp;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;OldManualSD&lt;SPAN&gt;&amp;gt; and&amp;nbsp;&amp;lt;\OldManualSD&amp;gt; tags, the 'after' list is between the&amp;nbsp;&amp;lt;NewManualSD&amp;gt; and&amp;nbsp;&amp;lt;/NewManualSD&amp;gt; tags&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;The Permissions field is between the ;; and ;;; delimiters and is followed by the SID. There is a varying number of permsissons/SIDs in each event&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;Can get part way there; ex_OldManual_GP and ex_NewManual_GP fields extract from the "Info" field and the contain the before and after, but trying to get a second extraction based off&amp;nbsp;ex_OldManual_GP and ex_NewManual_GP always fails&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;from the event above, I would like:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;OldManual = A;;CCDCLCSWRPWPDT;;;S-1-5-21-299502367-1960408961-839522117-10475&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;OldManual = A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406456&lt;BR /&gt;OldManual = A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406457&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;NewManual =&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;A;;CCDCLCSWRPWPDT;;;S-1-5-21-299502367-1960408961-839522117-10875&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;NewManual = A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406456&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;NewManual =&amp;nbsp;&lt;/SPAN&gt;A;;CCSW;;;S-1-5-21-299502367-1960408961-839522117-2406457&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;NewManua l= A;;CCDCSWRPDT;;;S-1-5-21-299502367-1960408961-839522117-3949147&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN&gt;my transforms.conf file:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ex_fields_extract]&lt;BR /&gt;FIELDS = "AuditDate","AuditID","Status","UserName","CategoryName","SubCategoryName","ObjectID","Vault","info","MachineName"&lt;BR /&gt;DELIMS = "\t"&lt;/P&gt;&lt;P&gt;[ex_OldManual_GP]&lt;BR /&gt;SOURCE_KEY = info&lt;BR /&gt;REGEX=\&amp;gt;(&amp;lt;OldManualSD&amp;gt;D:)((?P&amp;lt;OldManual_GP&amp;gt;.*))(&amp;lt;\/OldManualSD&amp;gt;)&lt;/P&gt;&lt;P&gt;[ex_NewManual_GP]&lt;BR /&gt;SOURCE_KEY = info&lt;BR /&gt;REGEX=\&amp;gt;(&amp;lt;NewManualSD&amp;gt;D:)((?P&amp;lt;NewManual_GP&amp;gt;.*))(&amp;lt;\/NewManualSD&amp;gt;)&lt;/P&gt;&lt;P&gt;[ex_OldManual_MV]&lt;BR /&gt;SOURCE_KEY = OldManual_GP&lt;BR /&gt;REGEX=;;(?P&amp;lt;perm&amp;gt;\w+);;;*&lt;BR /&gt;MV_ADD=true&lt;/P&gt;&lt;P&gt;[ex_NewManual_MV]&lt;BR /&gt;SOURCE_KEY = NewManual_GP&lt;BR /&gt;REGEX=(?&amp;lt;NewManual&amp;gt;[^,]+),*&lt;BR /&gt;MV_ADD=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my props.conf file&lt;/P&gt;&lt;P&gt;[exlogs]&lt;BR /&gt;REPORT-ex_fields = ex_fields_extract&lt;BR /&gt;REPORT-mvalue = ex_OldManual_MV, ex_NewManual_MV, ex_NewManual_GP, ex_OldManual_GP&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 17:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-regex-to-extract-multiple-values-between-tags/m-p/532363#M150386</guid>
      <dc:creator>capilarity</dc:creator>
      <dc:date>2020-12-08T17:41:07Z</dc:date>
    </item>
  </channel>
</rss>

