<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rex and extracted fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575491#M200542</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Your rex doesn't match your events - try this&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "Total TXNs:\s+(?&amp;lt;TxnsCount&amp;gt;\d+)#015"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry - my fault when trying to sanitise data to obscure process details&lt;/P&gt;&lt;P&gt;Re-edited...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="1346"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="1346"&gt;_raw&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:47:15.675045+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 47:15.5492|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|b18f74b5-6210-4294-802b-89c806f8cdcd|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:40:08.950766+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 40:08.8161|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|1311ded0-b556-4aba-8381-0a1ce89064ad|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:37:11.174909+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 37:11.0629|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|ca35e8e0-9ba9-46b0-9281-56d90bd337a9|BOTName|19|||||||||Total txns: 3#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:35:53.424646+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 35:53.2097|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|c671c0da-9dd4-421a-be40-845c9ed27021|BOTName|19|||||||||Total txns: 3#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T14:25:01.124036+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 24:59.4485|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|897c7235-4a92-4464-8062-0f35748b582a|BOTName|19|||||||||Total txns: 4#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T14:22:30.732755+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 22:30.5245|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|2ce1a155-0704-49b3-9c0e-24cab1d807d4|BOTName|19|||||||||Total txns: 7#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T12:58:08.374584+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 58:08.2601|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|16ef2534-2a29-4ad4-85c2-afbcaec77a5d|BOTName|19|||||||||Total txns: 112#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T12:48:35.557133+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 48:35.2166|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|320327f0-aa79-4f8f-a1d8-f28649da6297|BOTName|19|||||||||Total txns: 113#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T09:46:08.117037+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 46:07.9206|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|f0005ca4-22b1-4cf7-a3ec-ef4dc9ee685c|BOTName|19|||||||||Total txns: 22#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T09:37:46.727116+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 37:46.6463|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|15007061-2dc2-424f-8046-115b11ca2617|BOTName|19|||||||||Total txns: 31#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T09:25:33.222767+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 25:32.7040|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|58c03fe0-941b-41ec-841e-9b1602e1c806|BOTName|19|||||||||Total txns: 10#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T08:29:17.696167+00:00 &amp;lt;Removed&amp;gt;2021-11-18 08: 29:17.3912|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d29e1bb5-9ffa-4746-ae22-223bd1975a98|BOTName|19|||||||||Total txns: 10#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T17:40:17.998833+00:00 &amp;lt;Removed&amp;gt;2021-11-17 17: 40:17.1217|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|5164ec1c-5463-476a-873b-c16529d9ad98|BOTName|19|||||||||Total txns: 66#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:23:00.091137+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 22:59.9499|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d6a27318-89da-4815-a9bf-6de77adab50f|BOTName|19|||||||||Total txns: 3#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:22:49.715505+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 22:49.5033|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d6a27318-89da-4815-a9bf-6de77adab50f|BOTName|19|||||||||Total txns: 2#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:05:52.019927+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:51.4867|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:05:32.929245+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:31.3525|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:05:05.251231+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:02.5109|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;HR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Nov 2021 16:39:47 GMT</pubDate>
    <dc:creator>Mick_OBrien</dc:creator>
    <dc:date>2021-11-18T16:39:47Z</dc:date>
    <item>
      <title>rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575439#M200518</link>
      <description>&lt;P&gt;I have a search string that gives me count of txns processed by a job...&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;....| rex field=_raw "Total txns:(?&amp;lt;TxnsCount&amp;gt;.*)#015" | table _time, TxnsCount&lt;/P&gt;&lt;P&gt;...but when I try to extract txns where value greater than 10...&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;...| rex field=_raw "Total txns:(?&amp;lt;TxnsCount&amp;gt;.*)#015" | table _time, TxnsCount &lt;STRONG&gt;| where&amp;nbsp;TxnsCount &amp;gt; 10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;...no data is returned&lt;/P&gt;&lt;P&gt;Any help welcome&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 13:03:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575439#M200518</guid>
      <dc:creator>Mick_OBrien</dc:creator>
      <dc:date>2021-11-18T13:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575446#M200523</link>
      <description>&lt;P&gt;Are you sure there are events where TxnsCount is greater than 10?&amp;nbsp; Please share some sample (sanitized) events.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 13:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575446#M200523</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-18T13:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575449#M200525</link>
      <description>&lt;P&gt;Do you have leading/trailing spaces? Try:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "Total txns:(?&amp;lt;TxnsCount&amp;gt;.*)#015" | eval TxnsCount=trim(TxnsCount) | table _time, TxnsCount | where TxnsCount &amp;gt; 10&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 18 Nov 2021 14:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575449#M200525</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-11-18T14:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575463#M200529</link>
      <description>&lt;P&gt;There are txns with 500 [I remove the 'where' clause and I see them] and multiple lower digit txns [not of interested]&lt;/P&gt;&lt;P&gt;I tried trim command but that did not help - still no dataset returned&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 14:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575463#M200529</guid>
      <dc:creator>Mick_OBrien</dc:creator>
      <dc:date>2021-11-18T14:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575465#M200531</link>
      <description>&lt;P&gt;Can you share some events, otherwise, we are blindly guessing!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 14:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575465#M200531</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-11-18T14:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575485#M200539</link>
      <description>&lt;P&gt;Some events [sanitised]...&lt;/P&gt;&lt;TABLE width="1790"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T14:25:01.124036+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 24:59.4485|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|897c7235-4a92-4464-8062-0f35748b582a|BOTName|19|||||||||Total TXNs: 4#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T14:22:30.732755+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 22:30.5245|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|2ce1a155-0704-49b3-9c0e-24cab1d807d4|BOTName|19|||||||||Total TXNs: 7#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T14:22:08.971441+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 22:08.8370|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|2ce1a155-0704-49b3-9c0e-24cab1d807d4|BOTName|19|||||||||Total TXNs: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T14:17:26.722148+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 17:26.5446|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|b4db87da-a8f6-4fa6-a292-617c9823488d|BOTName|19|||||||||Total TXNs: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T14:12:55.708077+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 12:55.4094|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|ef394e25-0274-45a7-b209-5ac1dab8c46c|BOTName|19|||||||||Total TXNs: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T12:58:08.374584+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 58:08.2601|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|16ef2534-2a29-4ad4-85c2-afbcaec77a5d|BOTName|19|||||||||Total TXNs: 112#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T12:48:35.557133+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 48:35.2166|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|320327f0-aa79-4f8f-a1d8-f28649da6297|BOTName|19|||||||||Total TXNs: 113#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T09:46:44.959929+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 46:44.8054|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|f0005ca4-22b1-4cf7-a3ec-ef4dc9ee685c|BOTName|19|||||||||Total TXNs: 3#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T09:46:08.117037+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 46:07.9206|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|f0005ca4-22b1-4cf7-a3ec-ef4dc9ee685c|BOTName|19|||||||||Total TXNs: 22#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T09:41:09.172225+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 41:09.0983|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|39b311fa-e223-4e30-93b3-3774096313f3|BOTName|19|||||||||Total TXNs: 5#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T09:40:17.503636+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 40:17.1882|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|39b311fa-e223-4e30-93b3-3774096313f3|BOTName|19|||||||||Total TXNs: 4#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T09:37:59.351887+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 37:59.0219|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|15007061-2dc2-424f-8046-115b11ca2617|BOTName|19|||||||||Total TXNs: 4#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T08:57:55.157899+00:00 &amp;lt;Removed&amp;gt;2021-11-18 08: 57:54.9116|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|9721848f-7963-40f4-9f5e-0832da57b55c|BOTName|19|||||||||Total TXNs: 10#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T08:25:42.887812+00:00 &amp;lt;Removed&amp;gt;2021-11-18 08: 25:42.5543|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|a79e6366-a739-4c57-a4ec-26359730034a|BOTName|19|||||||||Total TXNs: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T08:25:07.681935+00:00 &amp;lt;Removed&amp;gt;2021-11-18 08: 25:07.4193|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|a79e6366-a739-4c57-a4ec-26359730034a|BOTName|19|||||||||Total TXNs: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="1790"&gt;2021-11-18T07:48:49.009846+00:00 &amp;lt;Removed&amp;gt;2021-11-18 07: 48:48.8747|INFO|Robot.tenantId:4.UiPath.Orchestrator.Application.Services.Logs.LogsWriter|&amp;lt;Removed&amp;gt;|ProcessName|4|e722d559-7a70-4ef8-a75b-63fa6841eb37|BOTName|19|||||||||Total TXNs: 31#015&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575485#M200539</guid>
      <dc:creator>Mick_OBrien</dc:creator>
      <dc:date>2021-11-18T16:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575488#M200541</link>
      <description>&lt;P&gt;Your rex doesn't match your events - try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "Total TXNs:\s+(?&amp;lt;TxnsCount&amp;gt;\d+)#015"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575488#M200541</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-11-18T16:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575491#M200542</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Your rex doesn't match your events - try this&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "Total TXNs:\s+(?&amp;lt;TxnsCount&amp;gt;\d+)#015"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry - my fault when trying to sanitise data to obscure process details&lt;/P&gt;&lt;P&gt;Re-edited...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="1346"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="1346"&gt;_raw&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:47:15.675045+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 47:15.5492|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|b18f74b5-6210-4294-802b-89c806f8cdcd|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:40:08.950766+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 40:08.8161|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|1311ded0-b556-4aba-8381-0a1ce89064ad|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:37:11.174909+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 37:11.0629|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|ca35e8e0-9ba9-46b0-9281-56d90bd337a9|BOTName|19|||||||||Total txns: 3#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T15:35:53.424646+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 35:53.2097|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|c671c0da-9dd4-421a-be40-845c9ed27021|BOTName|19|||||||||Total txns: 3#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T14:25:01.124036+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 24:59.4485|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|897c7235-4a92-4464-8062-0f35748b582a|BOTName|19|||||||||Total txns: 4#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T14:22:30.732755+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 22:30.5245|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|2ce1a155-0704-49b3-9c0e-24cab1d807d4|BOTName|19|||||||||Total txns: 7#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T12:58:08.374584+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 58:08.2601|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|16ef2534-2a29-4ad4-85c2-afbcaec77a5d|BOTName|19|||||||||Total txns: 112#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T12:48:35.557133+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 48:35.2166|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|320327f0-aa79-4f8f-a1d8-f28649da6297|BOTName|19|||||||||Total txns: 113#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T09:46:08.117037+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 46:07.9206|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|f0005ca4-22b1-4cf7-a3ec-ef4dc9ee685c|BOTName|19|||||||||Total txns: 22#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T09:37:46.727116+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 37:46.6463|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|15007061-2dc2-424f-8046-115b11ca2617|BOTName|19|||||||||Total txns: 31#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T09:25:33.222767+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 25:32.7040|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|58c03fe0-941b-41ec-841e-9b1602e1c806|BOTName|19|||||||||Total txns: 10#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-18T08:29:17.696167+00:00 &amp;lt;Removed&amp;gt;2021-11-18 08: 29:17.3912|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d29e1bb5-9ffa-4746-ae22-223bd1975a98|BOTName|19|||||||||Total txns: 10#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T17:40:17.998833+00:00 &amp;lt;Removed&amp;gt;2021-11-17 17: 40:17.1217|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|5164ec1c-5463-476a-873b-c16529d9ad98|BOTName|19|||||||||Total txns: 66#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:23:00.091137+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 22:59.9499|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d6a27318-89da-4815-a9bf-6de77adab50f|BOTName|19|||||||||Total txns: 3#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:22:49.715505+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 22:49.5033|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d6a27318-89da-4815-a9bf-6de77adab50f|BOTName|19|||||||||Total txns: 2#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:05:52.019927+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:51.4867|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:05:32.929245+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:31.3525|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-11-17T15:05:05.251231+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:02.5109|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;HR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575491#M200542</guid>
      <dc:creator>Mick_OBrien</dc:creator>
      <dc:date>2021-11-18T16:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575493#M200543</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="2021-11-18T15:47:15.675045+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 47:15.5492|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|b18f74b5-6210-4294-802b-89c806f8cdcd|BOTName|19|||||||||Total txns: 1#015
2021-11-18T15:40:08.950766+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 40:08.8161|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|1311ded0-b556-4aba-8381-0a1ce89064ad|BOTName|19|||||||||Total txns: 1#015
2021-11-18T15:37:11.174909+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 37:11.0629|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|ca35e8e0-9ba9-46b0-9281-56d90bd337a9|BOTName|19|||||||||Total txns: 3#015
2021-11-18T15:35:53.424646+00:00 &amp;lt;Removed&amp;gt;2021-11-18 15: 35:53.2097|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|c671c0da-9dd4-421a-be40-845c9ed27021|BOTName|19|||||||||Total txns: 3#015
2021-11-18T14:25:01.124036+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 24:59.4485|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|897c7235-4a92-4464-8062-0f35748b582a|BOTName|19|||||||||Total txns: 4#015
2021-11-18T14:22:30.732755+00:00 &amp;lt;Removed&amp;gt;2021-11-18 14: 22:30.5245|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|2ce1a155-0704-49b3-9c0e-24cab1d807d4|BOTName|19|||||||||Total txns: 7#015
2021-11-18T12:58:08.374584+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 58:08.2601|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|16ef2534-2a29-4ad4-85c2-afbcaec77a5d|BOTName|19|||||||||Total txns: 112#015
2021-11-18T12:48:35.557133+00:00 &amp;lt;Removed&amp;gt;2021-11-18 12: 48:35.2166|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|320327f0-aa79-4f8f-a1d8-f28649da6297|BOTName|19|||||||||Total txns: 113#015
2021-11-18T09:46:08.117037+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 46:07.9206|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|f0005ca4-22b1-4cf7-a3ec-ef4dc9ee685c|BOTName|19|||||||||Total txns: 22#015
2021-11-18T09:37:46.727116+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 37:46.6463|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|15007061-2dc2-424f-8046-115b11ca2617|BOTName|19|||||||||Total txns: 31#015
2021-11-18T09:25:33.222767+00:00 &amp;lt;Removed&amp;gt;2021-11-18 09: 25:32.7040|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|58c03fe0-941b-41ec-841e-9b1602e1c806|BOTName|19|||||||||Total txns: 10#015
2021-11-18T08:29:17.696167+00:00 &amp;lt;Removed&amp;gt;2021-11-18 08: 29:17.3912|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d29e1bb5-9ffa-4746-ae22-223bd1975a98|BOTName|19|||||||||Total txns: 10#015
2021-11-17T17:40:17.998833+00:00 &amp;lt;Removed&amp;gt;2021-11-17 17: 40:17.1217|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|5164ec1c-5463-476a-873b-c16529d9ad98|BOTName|19|||||||||Total txns: 66#015
2021-11-17T15:23:00.091137+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 22:59.9499|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d6a27318-89da-4815-a9bf-6de77adab50f|BOTName|19|||||||||Total txns: 3#015
2021-11-17T15:22:49.715505+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 22:49.5033|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|d6a27318-89da-4815-a9bf-6de77adab50f|BOTName|19|||||||||Total txns: 2#015
2021-11-17T15:05:52.019927+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:51.4867|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015
2021-11-17T15:05:32.929245+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:31.3525|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015
2021-11-17T15:05:05.251231+00:00 &amp;lt;Removed&amp;gt;2021-11-17 15: 05:02.5109|INFO|&amp;lt;Removed&amp;gt;|&amp;lt;Removed&amp;gt;|ProcessName|4|a78efcf6-a4c1-465b-aca2-b995d62d229f|BOTName|19|||||||||Total txns: 1#015"
| multikv noheader=t
| table _raw



| rex "Total txns:\s+(?&amp;lt;TxnsCount&amp;gt;\d+)#015"
| where TxnsCount &amp;gt; 10&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:48:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575493#M200543</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-11-18T16:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575494#M200544</link>
      <description>&lt;P&gt;Thanks - that worked!!&lt;/P&gt;&lt;P&gt;What does your rex syntax do that the syntax I used did not do?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575494#M200544</guid>
      <dc:creator>Mick_OBrien</dc:creator>
      <dc:date>2021-11-18T16:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575496#M200546</link>
      <description>&lt;P&gt;".*" is a greedy match whereas \d+ is only picking up 1 or more digits, also, the \s+ takes into account the leading spaces prior to the field so you only have digits left in the field, which makes it numeric, which can then be compared to a numeric value (10). It is usually better to be as specific as you can in the patterns.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 17:05:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575496#M200546</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-11-18T17:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: rex and extracted fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575508#M200549</link>
      <description>&lt;P&gt;Thanks for the explanation - I thought issue was with SPLUNK [and could not see why] when in the end it was the monster [T] rex&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 17:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rex-and-extracted-fields/m-p/575508#M200549</guid>
      <dc:creator>Mick_OBrien</dc:creator>
      <dc:date>2021-11-18T17:30:41Z</dc:date>
    </item>
  </channel>
</rss>

