<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295246#M160352</link>
    <description>&lt;P&gt;I tried as well, but not sure on it. here is the sample request, which I am trying to put it on a table (which results with error descp 1, 2 &amp;amp; 3). please advise.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2017 02:09:25 GMT</pubDate>
    <dc:creator>t964396</dc:creator>
    <dc:date>2017-07-05T02:09:25Z</dc:date>
    <item>
      <title>How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295240#M160346</link>
      <description>&lt;P&gt;Can you please help me on how to write a basic SPLUNK query which returns value A, B, C &amp;amp; D.&lt;/P&gt;

&lt;P&gt;here are the sample XML tags screenshot attached&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2017 23:51:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295240#M160346</guid>
      <dc:creator>t964396</dc:creator>
      <dc:date>2017-07-04T23:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295241#M160347</link>
      <description>&lt;P&gt;You're trying to extract these into one field? Or what are you expecting as an output? &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295241#M160347</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-05T00:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295242#M160348</link>
      <description>&lt;P&gt;trying to extract this output as a table&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295242#M160348</guid>
      <dc:creator>t964396</dc:creator>
      <dc:date>2017-07-05T00:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295243#M160349</link>
      <description>&lt;P&gt;Try something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rex "one\&amp;gt;(?&amp;lt;one&amp;gt;\w+)|two\&amp;gt;(?&amp;lt;two&amp;gt;\w+)"|table one two
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The regex should extract what is in the one and two nodes and put them in fields called one and two. &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:28:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295243#M160349</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-05T00:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295244#M160350</link>
      <description>&lt;P&gt;Thanks!, I tried but still, it returns only A, B.. but not C, D &amp;amp; E, F. &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295244#M160350</guid>
      <dc:creator>t964396</dc:creator>
      <dc:date>2017-07-05T00:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295245#M160351</link>
      <description>&lt;P&gt;wouldn't you want to use xpath or spath to deal with XML?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 01:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295245#M160351</guid>
      <dc:creator>cmisztur</dc:creator>
      <dc:date>2017-07-05T01:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295246#M160352</link>
      <description>&lt;P&gt;I tried as well, but not sure on it. here is the sample request, which I am trying to put it on a table (which results with error descp 1, 2 &amp;amp; 3). please advise.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 02:09:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295246#M160352</guid>
      <dc:creator>t964396</dc:creator>
      <dc:date>2017-07-05T02:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295247#M160353</link>
      <description>&lt;P&gt;I tried, but not sure on it. So I had written a query using rex as below, it returns only error code1  detail1 all the times.&lt;/P&gt;

&lt;P&gt;(one = code , two = detail)&lt;/P&gt;

&lt;P&gt;InterfaceResponse| &lt;BR /&gt;
rex "\(?.{2,60})&amp;lt;\/msg:succes" | where success = "false"  | &lt;BR /&gt;
rex "\(?.{2,60})&amp;lt;\/msg:cod" | &lt;BR /&gt;
rex "\(?.{10,60})&amp;lt;\/msg:cod" | &lt;BR /&gt;
rex "\(?.{10,60})&amp;lt;\/msg:cod" | &lt;BR /&gt;
rex "(?.{2,60})&amp;lt;\/msg:detai" | &lt;BR /&gt;
rex "(?.{10,60})&amp;lt;\/msg:detai" |&lt;BR /&gt;
rex "(?.{10,60})&amp;lt;\/msg:detai" |&lt;BR /&gt;
table MessageUUID success errorcode1 errorcode2 errorcode3 detail1 detail2 detail3&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 02:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295247#M160353</guid>
      <dc:creator>t964396</dc:creator>
      <dc:date>2017-07-05T02:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a basic SPLUNK query which returns value A, B, C &amp; D.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295248#M160354</link>
      <description>&lt;P&gt;when you tried xpath, what did you try? &lt;CODE&gt;|xpath outfield=one "//msg:XYS/msg:ONE"&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 11:52:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-basic-SPLUNK-query-which-returns-value-A-B-C-D/m-p/295248#M160354</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-05T11:52:56Z</dc:date>
    </item>
  </channel>
</rss>

