<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Regex help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/576651#M200960</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239785"&gt;@manishchoudhary&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240507"&gt;@bhargavi&lt;/a&gt;&amp;nbsp; any idea why&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have splunk search -&amp;nbsp;index=cloud EventName: "Error Occurred" XChangeToSalesForce | rename message as "Message" _time as Time | table Time,Message&lt;/P&gt;&lt;P&gt;When i search on splunk search, i get the below response&lt;/P&gt;&lt;P&gt;1637759064&amp;nbsp;&amp;nbsp;Multiple Terms found for the same agency. Agency code:&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when the email is sent, i get nothing on the message field . It is set as inline&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Message&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1637759064&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Mon, 29 Nov 2021 19:31:02 GMT</pubDate>
    <dc:creator>viksvig</dc:creator>
    <dc:date>2021-11-29T19:31:02Z</dc:date>
    <item>
      <title>Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574662#M200260</link>
      <description>&lt;P&gt;Hi, I have the search returning the event&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN class=""&gt;Nov&lt;/SPAN&gt; &lt;SPAN class=""&gt;10&lt;/SPAN&gt; &lt;SPAN class=""&gt;23:45:3 8888888&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Tra&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;9100&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; { &lt;/SPAN&gt;&lt;SPAN class=""&gt;EventName:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Error Occurred&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;BatchId:&lt;/SPAN&gt; &lt;SPAN class=""&gt;095cehcx-87ee-43f6-9663-c2fb833677a978&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;CorrelationId:&lt;/SPAN&gt; &lt;SPAN class=""&gt;5fghja26b9-fe73-78cb-342b-5123f2ec167896&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Payload:&lt;/SPAN&gt; &lt;SPAN class=""&gt;BusinessLogicException&lt;/SPAN&gt;&lt;SPAN&gt; { &lt;/SPAN&gt;&lt;SPAN class=""&gt;Message:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Lead&lt;/SPAN&gt; &lt;SPAN class=""&gt;0000000001VII6N00AX&lt;/SPAN&gt; &lt;SPAN class=""&gt;has&lt;/SPAN&gt; &lt;SPAN class=""&gt;an&lt;/SPAN&gt; &lt;SPAN class=""&gt;agency&lt;/SPAN&gt; &lt;SPAN class=""&gt;code&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;7&lt;/SPAN&gt; &lt;SPAN class=""&gt;digits.&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;Data:&lt;/SPAN&gt;&lt;SPAN&gt; [], &lt;/SPAN&gt;&lt;SPAN class=""&gt;InnerException:&lt;/SPAN&gt; &lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;TargetSite:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Void&lt;/SPAN&gt; &lt;SPAN class=""&gt;Validate&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;uya.QueryModels.Lead&lt;/SPAN&gt;&lt;SPAN&gt;), &lt;/SPAN&gt;&lt;SPAN class=""&gt;StackTrace:&lt;/SPAN&gt;&lt;SPAN&gt; " &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;uyu.Models.Lead.Validate&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;Lead&lt;/SPAN&gt; &lt;SPAN class=""&gt;queriedLead&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i extract only the content on the Message&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Message:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;SPAN class=""&gt;Lead&lt;/SPAN&gt; &lt;SPAN class=""&gt;0000000001VII6N00AX&lt;/SPAN&gt; &lt;SPAN class=""&gt;has&lt;/SPAN&gt; &lt;SPAN class=""&gt;an&lt;/SPAN&gt; &lt;SPAN class=""&gt;agency&lt;/SPAN&gt; &lt;SPAN class=""&gt;code&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;7&lt;/SPAN&gt; &lt;SPAN class=""&gt;digits&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;.:"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 21:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574662#M200260</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-11T21:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574667#M200262</link>
      <description>&lt;P&gt;It would help to know what you've tried so far.&lt;/P&gt;&lt;P&gt;See if this regex helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?&amp;lt;Message&amp;gt;Message: \\\"[^\\\"]+\\\")"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you only need the message itself, then try this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "Message: \\\"(?&amp;lt;Message&amp;gt;\\\"[^\\\"]+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 18:22:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574667#M200262</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-12T18:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574760#M200289</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Getting an error for the 1st search&lt;/P&gt;&lt;PRE&gt;| rex "(?&amp;lt;Message&amp;gt;Message: \\\"[^\\\\"]+\\\")"&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;Error in 'SearchParser': Missing a search command before '^'. Error at position '81' of search query 'search index=cloud EventName: "Error Occurred" | ...{snipped} {errorcontext = Message&amp;gt;"[^\\\\"]+)"}'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Getting error for&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;| rex "Message: \\\"(?&amp;lt;Message&amp;gt;"[^\\\\"]+)"&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;Mismatched ']'.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 16:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574760#M200289</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-12T16:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574781#M200293</link>
      <description>&lt;P&gt;Sorry about that.&amp;nbsp; I had the wrong number of escape characters.&amp;nbsp; Please try my revised answer.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 18:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574781#M200293</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-12T18:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574785#M200295</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240632"&gt;@viksvig&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please use the below regex value in order to extract the message field at search time. Also, in order to extract the message field for all the logs put this regex value in Setting --&amp;gt; Field extraction&amp;nbsp;&lt;BR /&gt;.*?Message:\s+"(?P&amp;lt;message&amp;gt;.*?)"&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Kindly let me know if it works fine in your environment&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 18:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574785#M200295</guid>
      <dc:creator>manishchoudhary</dc:creator>
      <dc:date>2021-11-12T18:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574804#M200299</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Please try the below regex.&lt;/P&gt;&lt;P&gt;|rex field=_raw "\sMessage\:(?P&amp;lt;Message&amp;gt;.*)\,\s\Data"&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2021 10:13:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/574804#M200299</guid>
      <dc:creator>bhargavi</dc:creator>
      <dc:date>2021-11-13T10:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/576058#M200746</link>
      <description>&lt;P&gt;It works in the search , but when it sends it as email alert, it only has the dates and the messagews are empty&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 16:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/576058#M200746</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-23T16:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/576060#M200748</link>
      <description>&lt;P&gt;It works in the search , but when it sends it as email alert, it only has the dates and the message field is empty&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 16:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/576060#M200748</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-23T16:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/576651#M200960</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239785"&gt;@manishchoudhary&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240507"&gt;@bhargavi&lt;/a&gt;&amp;nbsp; any idea why&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have splunk search -&amp;nbsp;index=cloud EventName: "Error Occurred" XChangeToSalesForce | rename message as "Message" _time as Time | table Time,Message&lt;/P&gt;&lt;P&gt;When i search on splunk search, i get the below response&lt;/P&gt;&lt;P&gt;1637759064&amp;nbsp;&amp;nbsp;Multiple Terms found for the same agency. Agency code:&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when the email is sent, i get nothing on the message field . It is set as inline&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Message&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1637759064&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 29 Nov 2021 19:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Regex-help/m-p/576651#M200960</guid>
      <dc:creator>viksvig</dc:creator>
      <dc:date>2021-11-29T19:31:02Z</dc:date>
    </item>
  </channel>
</rss>

