<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query regarding splunk field extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/67002#M16728</link>
    <description>&lt;P&gt;Figured out the issue. The field before empty has 2 angular braces &amp;lt;&lt;XXXX&gt;&amp;gt;. Now working fine. Thanks for the pointer.&lt;/XXXX&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2013 04:55:40 GMT</pubDate>
    <dc:creator>p_basanth</dc:creator>
    <dc:date>2013-03-20T04:55:40Z</dc:date>
    <item>
      <title>Query regarding splunk field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/66998#M16724</link>
      <description>&lt;P&gt;Using the below regex I was able to extract first7 fields &lt;BR /&gt;Need to extract the last 3 fields &lt;BR /&gt;How to skip the blank &amp;lt;&amp;gt; &amp;lt;&amp;gt; tags and continue?&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;&lt;U&gt;Sample Event:&lt;/U&gt;&lt;/B&gt;&lt;BR /&gt;&lt;PRE&gt;####(DateTime) (Info) (Health) (host.domain.name) (component1) (component2) ((anonymous)) () () (1363678659879) (BEA-310002) (54% of the total memory in the server is free)&lt;/PRE&gt;&lt;BR /&gt;The original event has angular braces &amp;lt;&amp;gt; as the field delimiter above. Due to browser compatibility i have changed them to normal braces()&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;&lt;U&gt;Regex working fine (first 7 fields):&lt;/U&gt;&lt;/B&gt;&lt;BR /&gt;&lt;PRE&gt;####&amp;lt;(?P&amp;lt; F1&amp;gt;[^&amp;gt;]+)&amp;gt; \s+&amp;lt;(?P&lt;F2&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME3&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME4&gt;[^.]+)[^&amp;lt;\n]&lt;EM&gt;&amp;lt;(?P&lt;FIELDNAME5&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME6&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME7&gt;[^&amp;gt;]+&amp;gt;)&amp;gt;&lt;/FIELDNAME7&gt;&lt;/FIELDNAME6&gt;&lt;/FIELDNAME5&gt;&lt;/EM&gt;&lt;/FIELDNAME4&gt;&lt;/FIELDNAME3&gt;&lt;/F2&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;&lt;U&gt;Below regex not working (after 7th field):&lt;/U&gt;&lt;/B&gt;&lt;BR /&gt;&lt;PRE&gt;####&amp;lt;(?P&amp;lt; FIELDNAME1&amp;gt;[^&amp;gt;]+)&amp;gt; \s+&amp;lt;(?P&lt;FIELDNAME2&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME3&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME4&gt;[^.]+)[^&amp;lt;\n]&amp;lt;(?P&lt;FIELDNAME5&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME6&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME7&gt;[^&amp;gt;]+&amp;gt;)&amp;gt;[^&amp;gt;\n]&lt;EM&gt;&amp;gt;\s[^&amp;gt;\n]&lt;/EM&gt;&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME8&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME9&gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?P&lt;FIELDNAME10&gt;[^&amp;gt;]+)&amp;gt;&lt;/FIELDNAME10&gt;&lt;/FIELDNAME9&gt;&lt;/FIELDNAME8&gt;&lt;/FIELDNAME7&gt;&lt;/FIELDNAME6&gt;&lt;/FIELDNAME5&gt;&lt;/FIELDNAME4&gt;&lt;/FIELDNAME3&gt;&lt;/FIELDNAME2&gt;&lt;/PRE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2013 04:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/66998#M16724</guid>
      <dc:creator>p_basanth</dc:creator>
      <dc:date>2013-03-20T04:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Query regarding splunk field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/66999#M16725</link>
      <description>&lt;P&gt;&lt;B&gt;Original sample Event:&lt;B&gt; &lt;BR /&gt; &lt;/B&gt;&lt;/B&gt;&lt;PRE&gt;&lt;B&gt;&lt;B&gt; ####&lt;MAR 19=""&gt; &lt;INFO&gt; &lt;HEALTH&gt; &lt;HOST.DOMAIN.NAME&gt; &lt;COMPONENT1&gt; &lt;COMPONENT2&gt; &amp;lt;&lt;ANONYMOUS&gt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;1363678659879&amp;gt; &lt;BEA-310002&gt; &amp;lt;54% of the total memory in the server is free&amp;gt;&lt;BR /&gt;
&lt;/BEA-310002&gt;&lt;/ANONYMOUS&gt;&lt;/COMPONENT2&gt;&lt;/COMPONENT1&gt;&lt;/HOST.DOMAIN.NAME&gt;&lt;/HEALTH&gt;&lt;/INFO&gt;&lt;/MAR&gt;&lt;/B&gt;&lt;/B&gt;&lt;/PRE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2013 04:07:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/66999#M16725</guid>
      <dc:creator>p_basanth</dc:creator>
      <dc:date>2013-03-20T04:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Query regarding splunk field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/67000#M16726</link>
      <description>&lt;P&gt;You need to change the '+' to a '*' in any field that can be empty.&lt;/P&gt;

&lt;P&gt;e.g:&lt;BR /&gt;
[^&amp;gt;]+ must match at least one character that is not '&amp;gt;'&lt;BR /&gt;
[^&amp;gt;]* can match no characters&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2013 04:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/67000#M16726</guid>
      <dc:creator>datasearchninja</dc:creator>
      <dc:date>2013-03-20T04:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Query regarding splunk field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/67001#M16727</link>
      <description>&lt;P&gt;No luck !! Tried '*' in the place of '+'. Not able to locate 3rd last field&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2013 04:34:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/67001#M16727</guid>
      <dc:creator>p_basanth</dc:creator>
      <dc:date>2013-03-20T04:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Query regarding splunk field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/67002#M16728</link>
      <description>&lt;P&gt;Figured out the issue. The field before empty has 2 angular braces &amp;lt;&lt;XXXX&gt;&amp;gt;. Now working fine. Thanks for the pointer.&lt;/XXXX&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2013 04:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Query-regarding-splunk-field-extraction/m-p/67002#M16728</guid>
      <dc:creator>p_basanth</dc:creator>
      <dc:date>2013-03-20T04:55:40Z</dc:date>
    </item>
  </channel>
</rss>

