<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extraction not working as expected in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extraction-not-working-as-expected/m-p/571630#M199197</link>
    <description>&lt;P&gt;Your regex won't work for events which have commas in the values since every comma is treated as a field separator.&lt;/P&gt;&lt;P&gt;You could try delimiter-based parsing. But if you really want a regex, you have to account for exceptions.&lt;/P&gt;&lt;P&gt;You can try, for example, something like:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?:([^",]+|"[^"]*"),){19}"(?&amp;lt;instance&amp;gt;[^"]+)",.*&lt;/LI-CODE&gt;&lt;P&gt;Of course it's a raw regex, if you want to put it as a string into a command, you have to escape the quotation marks.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2021 10:47:01 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-10-20T10:47:01Z</dc:date>
    <item>
      <title>Extraction not working as expected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-not-working-as-expected/m-p/571595#M199176</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract the below highlighted fields. However when I use the expression this is working right on one type of event but picking a different(underlined) field from other event. Please let me know what wrong I am doing here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(?:[^,]+,){19}\"(?&amp;lt;instance&amp;gt;[^,]+)\",.*&lt;BR /&gt;&lt;BR /&gt;Below is the event which is getting extracted as expected.&lt;/P&gt;&lt;P&gt;50271232,00004102,00000000,1600,"20210901225500","20210901225500",4,-1,-1,"SYSTEM","","psd217",46769357,"MS932","KAVS0260-I \x83W\x83\x87\x83u\x83l\x83b\x83g(AJSROOT1:/\x90V\x8A_\x96{\x94ԏ\x88\x97\x9D/\x92l\x8ED\x94\xAD\x8Ds/04_\x92l\x8ED\x8Ew\x8E\xA6\x83f\x81[\x83^\x98A\x8Cg_\x8CߑO1TAX:@5V689)\x82\xF0\x8AJ\x8En\x82\xB5\x82܂\xB7","Information","jp1admin","/APP/ABC/AJS2","JOBNET","&lt;STRONG&gt;Server2:/\x90V\x8A_\x96{\x94ԏ\x88\x97\x9D/\x92l\x8ED\x94\xAD\x8Ds/04_\x92l\x8ED\x8Ew\x8E\xA6\x83f\x81[\x83^\x98A\x8Cg_\x8CߑO1TAX&lt;/STRONG&gt;","JOBNET","AJSROOT1:/\x90V\x8A_\x96{\x94ԏ\x88\x97\x9D/\x92l\x8ED\x94\xAD\x8Ds/04_\x92l\x8ED\x8Ew\x8E\xA6\x83f\x81[\x83^\x98A\x8Cg_\x8CߑO1TAX","AJSROOT1:/\x90V\x8A_\x96{\x94ԏ\x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below highlighted is what I need to extract but the underlined is getting extracted.&lt;BR /&gt;50271228,00004105,00000000,3088,"20210901225446","20210901225446",4,-1,-1,"SYSTEM","","psd240",316413752,"MS932","KAVS0263-I \x83W\x83\x87\x83u(AJSROOT1:/\x90V\x8A_\x96{\x94ԏ\x88\x97\x9D/MCS/\x8AĎ\x8B/09_\x92\x8D\x95\xB6\x91\x97\x90M\x96\xA2\x8DX\x90V\x8D\x80\x96ڃ`\x83F\x83b\x83N/HULFT\x91\x97\x90M\x8C㎞\x8Aԑҋ@1MIN:@50R6189)\x82\xF0\x8AJ\x8En\x82\xB5\x82܂\xB7(host: PSD511, JOBID: 0)","Information","jp1admin","/App/ABC/AJS2","&lt;STRONG&gt;&lt;U&gt;JOB&lt;/U&gt;&lt;/STRONG&gt;","&lt;STRONG&gt;Server1:/\x90V\x8A_\x96{\x94ԏ\x88\x97\x9D/MCS/\x8AĎ\x8B/09_\x92\x8D\x95\xB6\x91\x97\x90M\x96\xA2\x8DX\x90V\x8D\x80\x96ڃ`\x83F\x83b\x83N/HULFT\x91\x97\x90M\x8C㎞\x8Aԑҋ@1MIN&lt;/STRONG&gt;","JOBNET","AJSROOT1:/\x90V\x8A_\x96{\x94ԏ\x88\x97\x9D/MCS/\x8AĎ\x8B/09_\x92\x8D\x95\xB6\x91\x97\x90M\x96\xA2\x8DX\x90V\x8D\x80\x96ڃ`\x83F\x83b\x83N","AJSROOT1:/\x90V\x8A_\x96{\x94ԏ\x88\x97\x9D/MCS/\x8AĎ\x8B/09_\x92\x8D\x95\xB6\x91\x97\x90M\x96\xA2\x8DX\x90V\x8D\x80\x96ڃ`\x83F\x83b\x83N/HULFT\&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 07:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-not-working-as-expected/m-p/571595#M199176</guid>
      <dc:creator>srinivas_gowda</dc:creator>
      <dc:date>2021-10-20T07:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction not working as expected</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-not-working-as-expected/m-p/571630#M199197</link>
      <description>&lt;P&gt;Your regex won't work for events which have commas in the values since every comma is treated as a field separator.&lt;/P&gt;&lt;P&gt;You could try delimiter-based parsing. But if you really want a regex, you have to account for exceptions.&lt;/P&gt;&lt;P&gt;You can try, for example, something like:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?:([^",]+|"[^"]*"),){19}"(?&amp;lt;instance&amp;gt;[^"]+)",.*&lt;/LI-CODE&gt;&lt;P&gt;Of course it's a raw regex, if you want to put it as a string into a command, you have to escape the quotation marks.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 10:47:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-not-working-as-expected/m-p/571630#M199197</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-20T10:47:01Z</dc:date>
    </item>
  </channel>
</rss>

