<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get instance name from source in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541817#M153430</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;That worked great. I ended up with&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=* "Initiating EnterpriseOne startup"&lt;BR /&gt;| rex "targets\\\(?&amp;lt;machine&amp;gt;[^\\\]+)" | table machine _time&lt;BR /&gt;| dedup machine&lt;BR /&gt;| sort machine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp; newbie, I appreciate your input.&lt;/P&gt;&lt;P&gt;I'm sure there is documentation out there somewhere. Now if I can just find it. ;^o&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bruce&lt;/P&gt;</description>
    <pubDate>Mon, 01 Mar 2021 16:54:19 GMT</pubDate>
    <dc:creator>bcalder</dc:creator>
    <dc:date>2021-03-01T16:54:19Z</dc:date>
    <item>
      <title>Get instance name from source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541784#M153411</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I am completely new to Splunk so I apologize if this has been asked/answered. I did review the past discussions but could not find a solution to my question.&lt;/P&gt;&lt;P&gt;I have incoming logs that look similar to this&lt;/P&gt;&lt;DIV class="jas MANDATORY"&gt;&lt;EM&gt;&lt;SPAN class="date"&gt;28 Feb 2021 13:53:23,815&lt;/SPAN&gt;&lt;SPAN class="level"&gt;[MANDATORY]&lt;/SPAN&gt;&lt;SPAN class="comp"&gt;[JAS]&lt;/SPAN&gt;&lt;SPAN class="msg"&gt;&lt;STRONG&gt;Initiating EnterpriseOne startup&lt;/STRONG&gt; using configuration location (default_path) as 'C:\jde_home\SCFHA\targets\&lt;STRONG&gt;HTML_PD1_82&lt;/STRONG&gt;\config'. &lt;/SPAN&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV class="jas MANDATORY"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="jas MANDATORY"&gt;&lt;SPAN class="msg"&gt;I would like to be able to search for the string "Initiating EnterpriseOne startup " and create a dashboard table showing the date, time and the substring&amp;nbsp;HTML_PD1_82. The idea being, I would like to keep track of when each machine was restarted.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="jas MANDATORY"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="jas MANDATORY"&gt;&lt;SPAN class="msg"&gt;Can anyone help with the Search pattern? Thanks in advance.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="jas MANDATORY"&gt;&lt;SPAN class="msg"&gt;Bruce&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 01 Mar 2021 14:50:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541784#M153411</guid>
      <dc:creator>bcalder</dc:creator>
      <dc:date>2021-03-01T14:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Get instance name from source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541806#M153424</link>
      <description>&lt;P&gt;Perhaps this will get you started.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=foo "Initiating EnterpriseOne startup"
| rex "targets\\\(?&amp;lt;machine&amp;gt;[^\\\]+)"
| table _time machine&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 01 Mar 2021 15:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541806#M153424</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-01T15:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Get instance name from source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541817#M153430</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;That worked great. I ended up with&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=* "Initiating EnterpriseOne startup"&lt;BR /&gt;| rex "targets\\\(?&amp;lt;machine&amp;gt;[^\\\]+)" | table machine _time&lt;BR /&gt;| dedup machine&lt;BR /&gt;| sort machine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp; newbie, I appreciate your input.&lt;/P&gt;&lt;P&gt;I'm sure there is documentation out there somewhere. Now if I can just find it. ;^o&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bruce&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 16:54:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541817#M153430</guid>
      <dc:creator>bcalder</dc:creator>
      <dc:date>2021-03-01T16:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Get instance name from source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541836#M153439</link>
      <description>&lt;P&gt;For documentation, see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Search/GetstartedwithSearch" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Search/GetstartedwithSearch &lt;/A&gt;and&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchReference/WhatsInThisManual" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchReference/WhatsInThisManual&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 18:23:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Get-instance-name-from-source/m-p/541836#M153439</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-01T18:23:45Z</dc:date>
    </item>
  </channel>
</rss>

