<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538811#M152355</link>
    <description>&lt;P&gt;both of those worked thank you !!!&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2021 18:17:52 GMT</pubDate>
    <dc:creator>tkerr1357</dc:creator>
    <dc:date>2021-02-05T18:17:52Z</dc:date>
    <item>
      <title>Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538803#M152349</link>
      <description>&lt;P&gt;hey all looking for some help pulling some digits via regex. I am looking to pull the numbers directly after Actual value(in the example event below 48). I would like to exclude the quotes and comma if possible.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;LogName=LoginPI&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Events&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EventCode=1300&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EventType=4&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ComputerName=RNBSVSIMGT02.rightnetworks.com&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SourceName=Login&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Exceeded&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Type=Information&lt;/SPAN&gt; &lt;SPAN class="t"&gt;RecordNumber=285782&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Keywords=Classic&lt;/SPAN&gt; &lt;SPAN class="t"&gt;TaskCategory=None&lt;/SPAN&gt; &lt;SPAN class="t"&gt;OpCode=Info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Message=&lt;/SPAN&gt;&lt;SPAN&gt;{ "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Description&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Total&lt;/SPAN&gt; &lt;SPAN class="t"&gt;login&lt;/SPAN&gt; &lt;SPAN class="t"&gt;time&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;48s&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class="t"&gt;threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;of&lt;/SPAN&gt; &lt;SPAN class="t"&gt;45s&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;6.67%&lt;/SPAN&gt;&lt;SPAN&gt;)", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Actual&lt;/SPAN&gt; &lt;SPAN class="t"&gt;value&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;48&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;value&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;45&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AccountId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;4c06e54e-ab5f-47a6-2cc7-08d807c9fae2&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AccountName&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;rightnetworks\\eloginpi049&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;LauncherName&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;RNBSVSI21&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Locale&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;English&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;United&lt;/SPAN&gt; &lt;SPAN class="t"&gt;States&lt;/SPAN&gt;&lt;SPAN&gt;)", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;RemotingProtocol&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Rdp&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Resolution&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1920&lt;/SPAN&gt; &lt;SPAN class="t"&gt;×&lt;/SPAN&gt; &lt;SPAN class="t"&gt;1080&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;ScaleFactor&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;100%&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;TargetHost&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;BPSQCP00S143&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;TargetOS&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Microsoft&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Windows&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2016&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Standard&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.0.14393&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1607&lt;/SPAN&gt;&lt;SPAN&gt;)", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;EnvironmentName&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;BPSQCP00S143&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;EnvironmentId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;06a3c4a2-6f73-4c54-94e9-08d8040960f8&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Title&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Login&lt;/SPAN&gt; &lt;SPAN class="t"&gt;time&lt;/SPAN&gt; &lt;SPAN class="t"&gt;threshold&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exceeded&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 17:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538803#M152349</guid>
      <dc:creator>tkerr1357</dc:creator>
      <dc:date>2021-02-05T17:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538804#M152350</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/34998"&gt;@tkerr1357&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please, try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "Actual\s+value\":\s+\"(?&amp;lt;actual_value&amp;gt;[^\"]+)\""&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/0CVPNF/1" target="_blank"&gt;https://regex101.com/r/0CVPNF/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 17:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538804#M152350</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-05T17:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538806#M152352</link>
      <description>&lt;P&gt;This may help..&lt;/P&gt;&lt;P&gt;|makeresults | eval _raw="LogName=LoginPI Events EventCode=1300 EventType=4 ComputerName=RNBSVSIMGT02.rightnetworks.com SourceName=Login Threshold Exceeded Type=Information RecordNumber=285782 Keywords=Classic TaskCategory=None OpCode=Info Message={ \"Description\": \"Total login time (48s) exceeded threshold of 45s (6.67%)\", \"Actual value\": \"48\", \"Threshold value\": \"45\", \"AccountId\": \"4c06e54e-ab5f-47a6-2cc7-08d807c9fae2\", \"AccountName\": \"rightnetworks\\eloginpi049\", \"LauncherName\": \"RNBSVSI21\", \"Locale\": \"English (United States)\", \"RemotingProtocol\": \"Rdp\", \"Resolution\": \"1920 × 1080\", \"ScaleFactor\": \"100%\", \"TargetHost\": \"BPSQCP00S143\", \"TargetOS\": \"Microsoft Windows Server 2016 Standard 10.0.14393 (1607)\", \"EnvironmentName\": \"BPSQCP00S143\", \"EnvironmentId\": \"06a3c4a2-6f73-4c54-94e9-08d8040960f8\", \"Title\": \"Login time threshold exceeded" | rex field=_raw "Actual value\\\":\s+\\\"(?&amp;lt;actual_value&amp;gt;\d+)"&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 17:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538806#M152352</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2021-02-05T17:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538811#M152355</link>
      <description>&lt;P&gt;both of those worked thank you !!!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 18:17:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help/m-p/538811#M152355</guid>
      <dc:creator>tkerr1357</dc:creator>
      <dc:date>2021-02-05T18:17:52Z</dc:date>
    </item>
  </channel>
</rss>

