<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: get substring from long raw string in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/get-substring-from-long-raw-string/m-p/70824#M17731</link>
    <description>&lt;P&gt;Many thanks Iguinn!&lt;BR /&gt;
Yes, I need to restrict only to events that contain a messageString but for now your hint works fine!&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2013 12:25:30 GMT</pubDate>
    <dc:creator>tsek13</dc:creator>
    <dc:date>2013-03-22T12:25:30Z</dc:date>
    <item>
      <title>get substring from long raw string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/get-substring-from-long-raw-string/m-p/70822#M17729</link>
      <description>&lt;P&gt;Hi guys, i am newbie in Splunk and i have the following indexed line:&lt;/P&gt;

&lt;P&gt;Mar 21 20:12:14 HOST program name: 2013-03-21 20:12:14,424 | INFO&amp;nbsp; | Event 'x.y|z.k|asdfvgh|sdfklsd|sdfsdtrwe|asafhwej|qoqwpeirw|' is not allowed. | sdfsdfsdfsd | sdfsdfwerwe thread #8 - Jfsdfsdfssd]&lt;/P&gt;

&lt;P&gt;How can I do this:&lt;BR /&gt;
 - get only x.y|z.k|asdfvgh|sdfklsd|sdfsdtrwe|asafhwej|qoqwpeirw&lt;BR /&gt;
 - put the string &lt;CODE&gt;x.y|.z.k... in new field (a =&lt;/CODE&gt;x.y|...)&lt;BR /&gt;
 - Remove duplicate values&lt;BR /&gt;
 - count all distinct strings&lt;BR /&gt;
 - generate chart or timechart or an hitmap with number of distinct strings&lt;/P&gt;

&lt;P&gt;Thanhs for all your suport&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 02:31:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/get-substring-from-long-raw-string/m-p/70822#M17729</guid>
      <dc:creator>tsek13</dc:creator>
      <dc:date>2013-03-22T02:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: get substring from long raw string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/get-substring-from-long-raw-string/m-p/70823#M17730</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yoursearchhere
| rex "Event \'(?&amp;lt;messageString&amp;gt;.*?)\' is not allowed."
| stats count by messageString
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yoursearchhere
| rex "Event \'(?&amp;lt;messageString&amp;gt;.*?)\' is not allowed."
| timechart distinct_count(messageString)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Replace "yoursearchhere" with whatever makes sense; that might mean something like &lt;CODE&gt;sourcetype=xyz&lt;/CODE&gt;&lt;BR /&gt;
Did you need to restrict the search only to events that actually contain a messageString?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 02:52:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/get-substring-from-long-raw-string/m-p/70823#M17730</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-03-22T02:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: get substring from long raw string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/get-substring-from-long-raw-string/m-p/70824#M17731</link>
      <description>&lt;P&gt;Many thanks Iguinn!&lt;BR /&gt;
Yes, I need to restrict only to events that contain a messageString but for now your hint works fine!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 12:25:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/get-substring-from-long-raw-string/m-p/70824#M17731</guid>
      <dc:creator>tsek13</dc:creator>
      <dc:date>2013-03-22T12:25:30Z</dc:date>
    </item>
  </channel>
</rss>

