<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extraction skipping within the value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extraction-skipping-within-the-value/m-p/577002#M201092</link>
    <description>&lt;P&gt;Your alert has a comma in so try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?:[^,]+,){14}(?&amp;lt;alert_description&amp;gt;\"[^\"]*\"),&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 08:42:06 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-12-02T08:42:06Z</dc:date>
    <item>
      <title>Extraction skipping within the value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-skipping-within-the-value/m-p/576994#M201090</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract a field from the below event and the extraction is missing the last part of the field. Please help in getting this extracted.&lt;/P&gt;&lt;P&gt;Event:&lt;/P&gt;&lt;P&gt;117691777,00004105,00000000,5064,"20211202100006","20211202100006",4,-1,-1,"SYSTEM","","IPSC002",94882466,"MS932",&lt;U&gt;&lt;STRONG&gt;"Server-I ジョブ(Server:/IZ_SSYS_DB/DAILY/MP7/MP_D41/物流ルートテーブルデータ送信:@20H7984)を開始します(host: Host, JOBID: 229589)"&lt;/STRONG&gt;&lt;/U&gt;,"Information","tdi01","/HITACHI/JP1/AJS2","JOB","AJSROOT1:/IZ_SSYS_DB/DAILY/MP7/MP_D41/物流ルートテーブルデータ送信","JOBNET","Server:/IZ_SSYS_DB/DAILY/MP7","Server:/IZ_SSYS_DB/DAILY/MP7/MP_D41/物流ルートテーブルデータ送信","START","20211202100006","","",16,"A0","Server:/IZ_SSYS_DB/DAILY","A1","MP7","A2","MP_D41/物流ルートテーブルデータ送信","A3","@20H7984","ACTION_VERSION","0600","B0","n","B1","2","B2","tdi01","B3","IPSC002","C0","IPSC202","C1","","C6","r","H2","188677","H3","pj","H4","q","PLATFORM","NT",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Extraction used:&lt;/P&gt;&lt;P&gt;(?:[^,]+,){14}(?&amp;lt;alert_description&amp;gt;[^,]+),&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the same extraction is working on the below event as expected.&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;117727680&lt;/SPAN&gt;,&lt;SPAN class=""&gt;00004103&lt;/SPAN&gt;,&lt;SPAN class=""&gt;00000000&lt;/SPAN&gt;,&lt;SPAN class=""&gt;5064&lt;/SPAN&gt;,"&lt;SPAN class=""&gt;20211202172828&lt;/SPAN&gt;","&lt;SPAN class=""&gt;20211202172828&lt;/SPAN&gt;",&lt;SPAN class=""&gt;4&lt;/SPAN&gt;,&lt;SPAN class=""&gt;-1&lt;/SPAN&gt;,&lt;SPAN class=""&gt;-1&lt;/SPAN&gt;,"&lt;SPAN class=""&gt;SYSTEM&lt;/SPAN&gt;","","&lt;SPAN class=""&gt;IPSC002&lt;/SPAN&gt;",&lt;SPAN class=""&gt;94918000&lt;/SPAN&gt;,"&lt;SPAN class=""&gt;MS932&lt;/SPAN&gt;","&lt;SPAN class=""&gt;Server-I&lt;/SPAN&gt; &lt;SPAN class=""&gt;ジ&lt;/SPAN&gt;&lt;SPAN class=""&gt;ョ&lt;/SPAN&gt;&lt;SPAN class=""&gt;ブ&lt;/SPAN&gt;&lt;SPAN class=""&gt;ネ&lt;/SPAN&gt;&lt;SPAN class=""&gt;ッ&lt;/SPAN&gt;&lt;SPAN class=""&gt;ト&lt;/SPAN&gt;(&lt;SPAN class=""&gt;Server:/HTHACHU/IJH03/IJH03:@20I8438&lt;/SPAN&gt;)&lt;SPAN class=""&gt;が&lt;/SPAN&gt;&lt;SPAN class=""&gt;正&lt;/SPAN&gt;&lt;SPAN class=""&gt;常&lt;/SPAN&gt;&lt;SPAN class=""&gt;終&lt;/SPAN&gt;&lt;SPAN class=""&gt;了&lt;/SPAN&gt;&lt;SPAN class=""&gt;し&lt;/SPAN&gt;&lt;SPAN class=""&gt;ま&lt;/SPAN&gt;&lt;SPAN class=""&gt;し&lt;/SPAN&gt;&lt;SPAN class=""&gt;た&lt;/SPAN&gt;","&lt;SPAN class=""&gt;Information&lt;/SPAN&gt;","&lt;SPAN class=""&gt;tdi01&lt;/SPAN&gt;","&lt;SPAN class=""&gt;/HITACHI/JP1/AJS2&lt;/SPAN&gt;","&lt;SPAN class=""&gt;JOBNET&lt;/SPAN&gt;","&lt;SPAN class=""&gt;AJSROOT1:/HTHACHU/IJH03/IJH03&lt;/SPAN&gt;","&lt;SPAN class=""&gt;JOBNET&lt;/SPAN&gt;","&lt;SPAN class=""&gt;AJSROOT1:/HTHACHU/IJH03/IJH03&lt;/SPAN&gt;","&lt;SPAN class=""&gt;AJSROOT1:/HTHACHU/IJH03/IJH03&lt;/SPAN&gt;","&lt;SPAN class=""&gt;END&lt;/SPAN&gt;","&lt;SPAN class=""&gt;20211202172827&lt;/SPAN&gt;","&lt;SPAN class=""&gt;20211202172828&lt;/SPAN&gt;","",&lt;SPAN class=""&gt;10&lt;/SPAN&gt;,"&lt;SPAN class=""&gt;A0&lt;/SPAN&gt;","&lt;SPAN class=""&gt;AJSROOT1:/HTHACHU/IJH03&lt;/SPAN&gt;","&lt;SPAN class=""&gt;A1&lt;/SPAN&gt;","&lt;SPAN class=""&gt;IJH03&lt;/SPAN&gt;","&lt;SPAN class=""&gt;A3&lt;/SPAN&gt;","&lt;SPAN class=""&gt;@20I8438&lt;/SPAN&gt;","&lt;SPAN class=""&gt;ACTION_VERSION&lt;/SPAN&gt;","&lt;SPAN class=""&gt;0600&lt;/SPAN&gt;","&lt;SPAN class=""&gt;B0&lt;/SPAN&gt;","&lt;SPAN class=""&gt;n&lt;/SPAN&gt;","&lt;SPAN class=""&gt;B1&lt;/SPAN&gt;","&lt;SPAN class=""&gt;0&lt;/SPAN&gt;","&lt;SPAN class=""&gt;B3&lt;/SPAN&gt;","&lt;SPAN class=""&gt;IPSC002&lt;/SPAN&gt;","&lt;SPAN class=""&gt;H2&lt;/SPAN&gt;","&lt;SPAN class=""&gt;853876&lt;/SPAN&gt;","&lt;SPAN class=""&gt;H3&lt;/SPAN&gt;","&lt;SPAN class=""&gt;n&lt;/SPAN&gt;","&lt;SPAN class=""&gt;PLATFORM&lt;/SPAN&gt;","&lt;SPAN class=""&gt;NT&lt;/SPAN&gt;",&lt;/P&gt;&lt;P&gt;Please help extract the highlighted field.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 08:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-skipping-within-the-value/m-p/576994#M201090</guid>
      <dc:creator>srinivas_gowda</dc:creator>
      <dc:date>2021-12-02T08:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction skipping within the value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-skipping-within-the-value/m-p/577002#M201092</link>
      <description>&lt;P&gt;Your alert has a comma in so try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?:[^,]+,){14}(?&amp;lt;alert_description&amp;gt;\"[^\"]*\"),&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 08:42:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-skipping-within-the-value/m-p/577002#M201092</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-02T08:42:06Z</dc:date>
    </item>
  </channel>
</rss>

