<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rex Help for fields extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296538#M175583</link>
    <description>&lt;P&gt;Which value do you want to extract?&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2017 16:12:17 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2017-02-13T16:12:17Z</dc:date>
    <item>
      <title>Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296536#M175581</link>
      <description>&lt;P&gt;Please help me with rex &lt;BR /&gt;
i have key and value in json format&lt;/P&gt;

&lt;P&gt;{"context":{&lt;BR /&gt;&lt;BR /&gt;
      "sessionID":"1234567890",&lt;BR /&gt;
      "eventSeverity":"Debug",&lt;BR /&gt;
      "msgType":"REQUEST",&lt;BR /&gt;
      "appID":"someServices",&lt;BR /&gt;
      "eventID":"START","msgPayload":{"inboundMsg":{"msgContentType":"{"idtypes":["ABCDE","ABC"],"userName":"someName"}"}}}}&lt;BR /&gt;
how to retrive fields out of it.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 15:55:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296536#M175581</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-02-13T15:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296537#M175582</link>
      <description>&lt;P&gt;if you can add&lt;BR /&gt;
&lt;CODE&gt;KV_MODE = json&lt;/CODE&gt;&lt;BR /&gt;
to your props.conf for this sourcetype it's going to save you a lot of trouble (extraction will be automatic).&lt;/P&gt;

&lt;P&gt;rex is most useful when automatic extraction fails; try the builtin functionality first.&lt;/P&gt;

&lt;P&gt;more details available here:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/124406/extracting-fields-from-json-file-format.html"&gt;https://answers.splunk.com/answers/124406/extracting-fields-from-json-file-format.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296537#M175582</guid>
      <dc:creator>sjalexander</dc:creator>
      <dc:date>2017-02-13T16:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296538#M175583</link>
      <description>&lt;P&gt;Which value do you want to extract?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:12:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296538#M175583</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-02-13T16:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296539#M175584</link>
      <description>&lt;P&gt;sessionID,eventSeverity,msgType,appID,eventID,msgPayload,inboundMsg,msgContentType,idtypes,userName&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296539#M175584</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-02-13T16:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296540#M175585</link>
      <description>&lt;P&gt;I need during search time. &lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:15:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296540#M175585</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-02-13T16:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296541#M175586</link>
      <description>&lt;P&gt;Is this _raw or a field?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296541#M175586</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-13T16:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296542#M175587</link>
      <description>&lt;P&gt;Yes,this is _raw field&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296542#M175587</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-02-13T16:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296543#M175588</link>
      <description>&lt;P&gt;Try like this. The rex-sed command is requires as your data seems to have extra double quotes making it not pure json.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your current search which includes field _raw | rex mode=sed "s/\"{/{/g" | spath
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:28:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296543#M175588</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-13T16:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296544#M175589</link>
      <description>&lt;P&gt;understood. If this is something you're going to do on an ongoing basis, it's still a very good idea to get this stuff indexed in a usable manner instead of relying on searchtime hacks. If it's a one-off, carry on &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 16:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296544#M175589</guid>
      <dc:creator>sjalexander</dc:creator>
      <dc:date>2017-02-13T16:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296545#M175590</link>
      <description>&lt;P&gt;I'd recommend &lt;CODE&gt;kv_mode=json&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;But if you want to see how it's done then here ya go &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex sessionID\"\:\"(?&amp;lt;SessionID&amp;gt;\d+)
... | rex eventSeverity\"\:\"(?&amp;lt;EventSeverity&amp;gt;\w+)
... | rex msgType\"\:\"(?&amp;lt;msgType&amp;gt;\w+)
... | rex appID\"\:\"(?&amp;lt;AppID&amp;gt;\w+)
... | rex eventID\"\:\"(?&amp;lt;EventID&amp;gt;\w+)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Feb 2017 17:29:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296545#M175590</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-02-13T17:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296546#M175591</link>
      <description>&lt;P&gt;"idtypes":["ABCDE","XYZ"]&lt;/P&gt;

&lt;P&gt;how to write for this &lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 17:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296546#M175591</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-02-13T17:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296547#M175592</link>
      <description>&lt;P&gt;what do you want to extract?   ABCDE or XYZ, or the whole string ABCDE,XYZ?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 18:12:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296547#M175592</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2017-02-13T18:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296548#M175593</link>
      <description>&lt;P&gt;["ABCDE","XYZ"]&lt;/P&gt;

&lt;P&gt;entire this value&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 18:22:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296548#M175593</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-02-13T18:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296549#M175594</link>
      <description>&lt;P&gt;try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"idtypes":(?&amp;lt;idtypes&amp;gt;\S+)[,]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Feb 2017 18:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296549#M175594</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2017-02-13T18:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Rex Help for fields extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296550#M175595</link>
      <description>&lt;P&gt;Here ya go. If this answered your question, can you please accept it? &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;idtypes":\["(?&amp;lt;Name1&amp;gt;\w+)"\,"(?&amp;lt;Name2&amp;gt;\w+)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 20:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-Help-for-fields-extraction/m-p/296550#M175595</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-02-13T20:08:20Z</dc:date>
    </item>
  </channel>
</rss>

