<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Searches separated by Colon in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558730#M158743</link>
    <description>&lt;P&gt;Hi, Thanks for your reply, I think my issue is due to quotes within quotes? No sure. Below is a sample of my search. Basically everything in red is a sample what i am searching for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[{"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruName&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Modem&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruType&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;MBR&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruMacAddress&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;00:A0:BC:72:6F:44&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruModelNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;MBR-5500&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruSerialNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;C80016506037&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruPartNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;1244523&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruSoftwareVersion&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;M3-1.3.5.2.89_2021.06.18&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruConfigVersion&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t h"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;7.10.0.38&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jul 2021 16:41:08 GMT</pubDate>
    <dc:creator>ekucevic</dc:creator>
    <dc:date>2021-07-08T16:41:08Z</dc:date>
    <item>
      <title>Searches separated by Colon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558444#M158635</link>
      <description>&lt;P&gt;I source database that displays all of the info i need that is separated by colon. Example "i&lt;SPAN class="t a h"&gt;&lt;SPAN class="t"&gt;lruPartNumber&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;12345&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"., "&lt;SPAN class="t"&gt;lruSoftwareVersion&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;"&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;7.10.0&lt;/SPAN&gt;.&lt;SPAN class="t"&gt;74&lt;/SPAN&gt;&lt;/SPAN&gt;". All of the info i need is separated&amp;nbsp;by an " : "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;What i want is to separate&amp;nbsp;the search to list the Name then Number. Example&amp;nbsp;i&lt;SPAN class="t a h"&gt;&lt;SPAN class="t"&gt;lruPartNumber = 12345.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 16:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558444#M158635</guid>
      <dc:creator>ekucevic</dc:creator>
      <dc:date>2021-07-06T16:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Searches separated by Colon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558448#M158637</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "\"(?&amp;lt;key&amp;gt;[^\"]+)\":\"(?&amp;lt;value&amp;gt;[^\"]+)\""
| eval {key}=value&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 06 Jul 2021 16:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558448#M158637</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-06T16:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Searches separated by Colon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558478#M158645</link>
      <description>&lt;LI-SPOILER&gt;I am a beginner here so alittle bit of a walk through could be necessary.&amp;nbsp;&lt;/LI-SPOILER&gt;</description>
      <pubDate>Tue, 06 Jul 2021 21:11:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558478#M158645</guid>
      <dc:creator>ekucevic</dc:creator>
      <dc:date>2021-07-06T21:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Searches separated by Colon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558484#M158648</link>
      <description>&lt;P&gt;The rex command (without a field argument) will operate on the _raw field of each event. The regex used extracts the part before the colon into a field called key and the part afterwards into a field called value. The eval command creates a field using the name in the key field and with the value from the value field. This is the basis for extracting the field. If you want a more precise version of the command, you should share some anonymised events, that you have already retrieved with your search, so the command can be tailored to your specific case.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 22:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558484#M158648</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-06T22:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Searches separated by Colon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558730#M158743</link>
      <description>&lt;P&gt;Hi, Thanks for your reply, I think my issue is due to quotes within quotes? No sure. Below is a sample of my search. Basically everything in red is a sample what i am searching for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[{"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruName&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Modem&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruType&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;MBR&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruMacAddress&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;00:A0:BC:72:6F:44&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruModelNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;MBR-5500&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruSerialNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;C80016506037&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruPartNumber&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;1244523&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruSoftwareVersion&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;M3-1.3.5.2.89_2021.06.18&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;lruConfigVersion&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t h"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;7.10.0.38&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 16:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558730#M158743</guid>
      <dc:creator>ekucevic</dc:creator>
      <dc:date>2021-07-08T16:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Searches separated by Colon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558740#M158749</link>
      <description>&lt;P&gt;This looks like JSON, perhaps you should investigate spath as a way to extract the fields&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 18:01:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searches-separated-by-Colon/m-p/558740#M158749</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-08T18:01:35Z</dc:date>
    </item>
  </channel>
</rss>

