<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help me extract this data and create a table. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575884#M200685</link>
    <description>&lt;P class="lia-align-justify"&gt;Lets say i dont want to add in a 3rd field, I find that when i just change one of the components of your solution from "&lt;SPAN&gt;lruHwPartNumber" to "lruHwSerialNumber" it doesnt give me any results.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Nov 2021 14:36:14 GMT</pubDate>
    <dc:creator>ekucevic</dc:creator>
    <dc:date>2021-11-22T14:36:14Z</dc:date>
    <item>
      <title>Help me extract this data and create a table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575722#M200606</link>
      <description>&lt;P&gt;I have a log sample:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;| &lt;/SPAN&gt;&lt;SPAN class=""&gt;LRU&lt;/SPAN&gt; &lt;SPAN class=""&gt;Config&lt;/SPAN&gt; &lt;SPAN class=""&gt;Message&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;RMQ:&lt;/SPAN&gt;&lt;SPAN&gt; {"&lt;/SPAN&gt;&lt;SPAN class=""&gt;endpoint&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;lru/ config&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;data&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1637322539.953&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;version&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;aircraftTailId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;N123JB&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;/SPAN&gt;&lt;SPAN&gt;[{"&lt;/SPAN&gt;&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruComponent&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Modem&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruHwPartNumber&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;123456&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;lruHwSerialNumber&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;C82821190191&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruRevisionNumber&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;004&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruMacAddress&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;true&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;},&amp;nbsp;{"&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruComponent&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;","&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruHwPartNumber&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;1244632&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;","&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;lruHwSerialNumber&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;F39718480040&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;","&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruRevisionNumber&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;004&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;","&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruMacAddress&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;SPAN class=""&gt;:&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;null&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;},&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What i want to do is extract the date and create a table based on the color i highlighted above.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#00CCFF"&gt;&lt;SPAN class=""&gt;lruComponent&amp;nbsp; |&amp;nbsp;&amp;nbsp;lruHwPartNumber |&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Modem&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;123456&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 19:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575722#M200606</guid>
      <dc:creator>ekucevic</dc:creator>
      <dc:date>2021-11-19T19:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Help me extract this data and create a table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575733#M200612</link>
      <description>&lt;P&gt;See if this sample query helps.&amp;nbsp; It uses &lt;FONT face="courier new,courier"&gt;rex&lt;/FONT&gt; to extract the field values, &lt;FONT face="courier new,courier"&gt;mvzip&lt;/FONT&gt; to pair component with part number, then splits them back out for display.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="LRU Config Message from RMQ: {\"endpoint\":\"lru/ config\", \"data\":{\"timestamp\":1637322539.953,\"version\":\"1\",\"aircraftTailId\":\"N123JB\",[{\"lruComponent\":\"Modem\",\"lruHwPartNumber\":\"123456\",\"lruHwSerialNumber\":\"C82821190191\",\"lruRevisionNumber\":\"004\",\"lruMacAddress\":true}, {\"lruComponent\":\"Server\",\"lruHwPartNumber\":\"1244632\",\"lruHwSerialNumber\":\"F39718480040\",\"lruRevisionNumber\":\"004\",\"lruMacAddress\":null},"
```The above is just for testing```
| rex max_match=0 "lruComponent\\\":\\\"(?&amp;lt;lruComponent&amp;gt;[^\\\"]+)\\\",\\\"lruHwPartNumber\\\":\\\"(?&amp;lt;lruHwPartNumber&amp;gt;[^\\\"]+)"
| eval compNum=mvzip(lruComponent,lruHwPartNumber,",")
| mvexpand compNum
| eval compNum=split(compNum,",")
| eval lruComponent=mvindex(compNum,0), lruHwPartNumber=mvindex(compNum,1)
| table lruComponent lruHwPartNumber&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 20:37:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575733#M200612</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-19T20:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: Help me extract this data and create a table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575790#M200644</link>
      <description>&lt;P&gt;This is exactly what i was looking for. Really appreciate it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more thing, i want to add in 3rd column, "&lt;SPAN&gt;lruHwSerialNumber" and also these "lruHwSerialNumber"s&amp;nbsp; change over time. When i add in the serial number column will "Dedup _lruHwSerialNumber" work?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Nov 2021 15:14:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575790#M200644</guid>
      <dc:creator>ekucevic</dc:creator>
      <dc:date>2021-11-21T15:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Help me extract this data and create a table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575796#M200646</link>
      <description>&lt;P&gt;You can add a 3rd column, just be aware the &lt;FONT face="courier new,courier"&gt;mvzip&lt;/FONT&gt; function only accepts two arguments.&amp;nbsp; You can, however, nest &lt;FONT face="courier new,courier"&gt;mvzip&lt;/FONT&gt; calls.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchReference/MultivalueEvalFunctions#Extended_example_3" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchReference/MultivalueEvalFunctions#Extended_example_3&lt;/A&gt;&amp;nbsp;for an example of that.&lt;/P&gt;&lt;P&gt;Dedup should work, but I'd have to know more about how you plan to use to say for sure.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Nov 2021 19:08:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575796#M200646</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-21T19:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Help me extract this data and create a table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575884#M200685</link>
      <description>&lt;P class="lia-align-justify"&gt;Lets say i dont want to add in a 3rd field, I find that when i just change one of the components of your solution from "&lt;SPAN&gt;lruHwPartNumber" to "lruHwSerialNumber" it doesnt give me any results.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 14:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575884#M200685</guid>
      <dc:creator>ekucevic</dc:creator>
      <dc:date>2021-11-22T14:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Help me extract this data and create a table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575889#M200690</link>
      <description>&lt;P&gt;Substituting random fields won't work if the new field is not extracted.&amp;nbsp; Try this query.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="LRU Config Message from RMQ: {\"endpoint\":\"lru/ config\", \"data\":{\"timestamp\":1637322539.953,\"version\":\"1\",\"aircraftTailId\":\"N123JB\",[{\"lruComponent\":\"Modem\",\"lruHwPartNumber\":\"123456\",\"lruHwSerialNumber\":\"C82821190191\",\"lruRevisionNumber\":\"004\",\"lruMacAddress\":true}, {\"lruComponent\":\"Server\",\"lruHwPartNumber\":\"1244632\",\"lruHwSerialNumber\":\"F39718480040\",\"lruRevisionNumber\":\"004\",\"lruMacAddress\":null},"
```The above is just for testing```
| rex max_match=0 "lruComponent\\\":\\\"(?&amp;lt;lruComponent&amp;gt;[^\\\"]+)\\\",\\\"lruHwPartNumber\\\":\\\"(?&amp;lt;lruHwPartNumber&amp;gt;[^\\\"]+)\\\",\\\"lruHwSerialNumber\\\":\\\"(?&amp;lt;lruHwSerialNumber&amp;gt;[^\\\"]+)"
| eval compNum=mvzip(lruComponent,lruHwSerialNumber,",")
| mvexpand compNum
| eval compNum=split(compNum,",")
| eval lruComponent=mvindex(compNum,0), lruHwSerialNumber=mvindex(compNum,1)
| table lruComponent lruHwSerialNumber&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 22 Nov 2021 14:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/575889#M200690</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-22T14:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help me extract this data and create a table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/576079#M200757</link>
      <description>&lt;P&gt;I am going to accept this solution. Really appreciate your help.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;One thing i noticed is these are periodic logs and usually the serial numbers can change. I added dedup&amp;nbsp;lruHwSerialNumber thinking it would pull the different serial based on the time frame i know it changed but it doesnt seem to pull it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 20:05:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-me-extract-this-data-and-create-a-table/m-p/576079#M200757</guid>
      <dc:creator>ekucevic</dc:creator>
      <dc:date>2021-11-23T20:05:35Z</dc:date>
    </item>
  </channel>
</rss>

