<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field extraction from pre-defined text in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457853#M170455</link>
    <description>&lt;P&gt;Wa'salam brother. Glad it helped!&lt;/P&gt;</description>
    <pubDate>Sun, 14 Jul 2019 22:51:01 GMT</pubDate>
    <dc:creator>nabeel652</dc:creator>
    <dc:date>2019-07-14T22:51:01Z</dc:date>
    <item>
      <title>Field extraction from pre-defined text</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457849#M170451</link>
      <description>&lt;P&gt;I have a text file in below format. We are monitoring this file in Splunk. This file has like entries in new lines with different values but in exact same format. This data is a fixed format already defined.&lt;/P&gt;

&lt;P&gt;fR0226672024ABCOL41333311023S02315201801  UID03&lt;/P&gt;

&lt;P&gt;I need to extract data based on the position labeled in fields properly as below. Using sample data above. Th actual sample is different and I will adjust as needed. I need to have the foundation work.&lt;/P&gt;

&lt;P&gt;f: Center Code&lt;BR /&gt;
R: Mode&lt;BR /&gt;
0226672024: ID&lt;BR /&gt;
ABC: Application&lt;BR /&gt;
OL: Source Code&lt;BR /&gt;
41333311023: Version&lt;BR /&gt;
S0: Department&lt;BR /&gt;
23: Day&lt;BR /&gt;
10: Month&lt;BR /&gt;
2018: Year&lt;BR /&gt;
01: Sequence&lt;BR /&gt;
(&amp;gt;&amp;gt;): Two spaces for position&lt;BR /&gt;
UID03: UID&lt;/P&gt;

&lt;P&gt;How to have it extracted in above manner. Thanks in-advance!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 01:23:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457849#M170451</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2019-07-09T01:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from pre-defined text</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457850#M170452</link>
      <description>&lt;P&gt;are the fields like ID and SourceCode or Version of same length in each event?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 01:43:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457850#M170452</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2019-07-09T01:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from pre-defined text</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457851#M170453</link>
      <description>&lt;P&gt;Assuming all your fields are of fixed length across all events, this regex whould work in the field extractions&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;^(?&amp;lt;CentreCode&amp;gt;\w)(?&amp;lt;Mode&amp;gt;\w)(?&amp;lt;ID&amp;gt;\d{10})(?&amp;lt;Application&amp;gt;\w{3})(?&amp;lt;SourceCode&amp;gt;\w{2})(?&amp;lt;Version&amp;gt;\w{11})(?&amp;lt;Department&amp;gt;.{2})(?&amp;lt;Day&amp;gt;\d{2})(?&amp;lt;Month&amp;gt;\d{2})(?&amp;lt;Year&amp;gt;\d{4})(?&amp;lt;Sequence&amp;gt;.{2})\s+(?&amp;lt;UID&amp;gt;.*)$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Jul 2019 03:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457851#M170453</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2019-07-09T03:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from pre-defined text</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457852#M170454</link>
      <description>&lt;P&gt;salam @ nabeel652,&lt;/P&gt;

&lt;P&gt;with slight adjustment in use case, this worked with fixed position. THANKS!!! I have another challenging situation come up yesterday for RegEx. Will be posting a separate question tonight.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2019 20:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457852#M170454</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2019-07-13T20:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from pre-defined text</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457853#M170455</link>
      <description>&lt;P&gt;Wa'salam brother. Glad it helped!&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2019 22:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-pre-defined-text/m-p/457853#M170455</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2019-07-14T22:51:01Z</dc:date>
    </item>
  </channel>
</rss>

