<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Require help with rex query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Require-help-with-rex-query/m-p/539089#M152474</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the below type of logs:&lt;/P&gt;&lt;P&gt;log1:&amp;nbsp;Mon Feb 8 02:57:36 EST 2021 41% /logs&lt;/P&gt;&lt;P&gt;log2:&amp;nbsp;&lt;SPAN class="t"&gt;Mon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Feb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02:57:36&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EST&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;73%&lt;/SPAN&gt; &lt;SPAN class="t"&gt;/opt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;log3:&amp;nbsp;&lt;SPAN class="t"&gt;Mon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Feb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02:57:36&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EST&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;69%&lt;/SPAN&gt; &lt;SPAN class="t"&gt;/var&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;log4:&amp;nbsp;&lt;SPAN class="t"&gt;Mon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Feb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02:57:36&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EST&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;48%&lt;/SPAN&gt; &lt;SPAN class="t"&gt;/apps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I want to create a table as below:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;File_System&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Disk_Usage&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;\logs&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;41&lt;/P&gt;&lt;P&gt;\opt&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 73&lt;/P&gt;&lt;P&gt;\var&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;69&lt;/P&gt;&lt;P&gt;\apps&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;48&lt;/P&gt;&lt;P&gt;Here I want to extract the "Disk_Usage" and "File_System" fields with the respective values. This might be a very silly question but I might be missing out something while creating the rex command. So please help me create the rex command. you kind support will be highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Feb 2021 04:37:09 GMT</pubDate>
    <dc:creator>Mrig342</dc:creator>
    <dc:date>2021-02-09T04:37:09Z</dc:date>
    <item>
      <title>Require help with rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Require-help-with-rex-query/m-p/539089#M152474</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the below type of logs:&lt;/P&gt;&lt;P&gt;log1:&amp;nbsp;Mon Feb 8 02:57:36 EST 2021 41% /logs&lt;/P&gt;&lt;P&gt;log2:&amp;nbsp;&lt;SPAN class="t"&gt;Mon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Feb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02:57:36&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EST&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;73%&lt;/SPAN&gt; &lt;SPAN class="t"&gt;/opt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;log3:&amp;nbsp;&lt;SPAN class="t"&gt;Mon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Feb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02:57:36&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EST&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;69%&lt;/SPAN&gt; &lt;SPAN class="t"&gt;/var&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;log4:&amp;nbsp;&lt;SPAN class="t"&gt;Mon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Feb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02:57:36&lt;/SPAN&gt; &lt;SPAN class="t"&gt;EST&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;48%&lt;/SPAN&gt; &lt;SPAN class="t"&gt;/apps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I want to create a table as below:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;File_System&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Disk_Usage&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;\logs&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;41&lt;/P&gt;&lt;P&gt;\opt&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 73&lt;/P&gt;&lt;P&gt;\var&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;69&lt;/P&gt;&lt;P&gt;\apps&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;48&lt;/P&gt;&lt;P&gt;Here I want to extract the "Disk_Usage" and "File_System" fields with the respective values. This might be a very silly question but I might be missing out something while creating the rex command. So please help me create the rex command. you kind support will be highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 04:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Require-help-with-rex-query/m-p/539089#M152474</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2021-02-09T04:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Require help with rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Require-help-with-rex-query/m-p/539090#M152475</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230871"&gt;@Mrig342&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Try this,&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw=" _raw
Mon Feb 8 02:57:36 EST 2021 41% /logs
Mon Feb 8 02:57:36 EST 2021 73% /opt
Mon Feb 8 02:57:36 EST 2021 69% /var
Mon Feb 8 02:57:36 EST 2021 48% /apps" 
| multikv forceheader=1 
| rex "\s(?&amp;lt;Disk_Usage&amp;gt;\d+)\%\s\/(?&amp;lt;File_System&amp;gt;\w+)" 
| table File_System, Disk_Usage&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you, an upvote/like would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 05:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Require-help-with-rex-query/m-p/539090#M152475</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-02-09T05:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Require help with rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Require-help-with-rex-query/m-p/539092#M152476</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129090"&gt;@manjunathmeti&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 05:52:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Require-help-with-rex-query/m-p/539092#M152476</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2021-02-09T05:52:04Z</dc:date>
    </item>
  </channel>
</rss>

