<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract fields from non-JSON formatted data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579165#M201834</link>
    <description>&lt;P&gt;Hi richgalloway, Thanks for you reply.&lt;/P&gt;&lt;P&gt;Unfortunately when I for example try to table the results I do not receive any results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Base search ....
| rex "order_id\\\":\s\\\"(?&amp;lt;order_id&amp;gt;[^\\\"]+)"
| table order_id&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 23 Dec 2021 08:42:22 GMT</pubDate>
    <dc:creator>Matthew86</dc:creator>
    <dc:date>2021-12-23T08:42:22Z</dc:date>
    <item>
      <title>Extract fields from non-JSON formatted data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579122#M201817</link>
      <description>&lt;P&gt;Hi Guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope you can help me out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the following data in Splunk:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{ 
   attrs: { 
     account: 85859303
     version: 1.3848
   }
   line: { 
     application_version: 1.94949303
     message: Event with key 84js9393: {"entity": {"customer_id": "K123456", "order_id": "Sjd49493-93nd-9494-jdjd-mskaldjfhfhh", "collection_id": "djdis939-9398-9488-j939-md839md93000", "issuer_id": null}}
     thread: springfield
     timestamp: 2021-12-21 19:30:52,123
   }
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to extract the order_id and use it in my search:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;order_id=Sjd49493-93nd-9494-jdjd-mskaldjfhfhh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope someone can help or point me in the right direction.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Cheers!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matthew&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 17:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579122#M201817</guid>
      <dc:creator>Matthew86</dc:creator>
      <dc:date>2021-12-22T17:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Extract fields from non-JSON formatted data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579124#M201818</link>
      <description>&lt;P&gt;It's easy with rex&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | rex "order_id\\\":\s\\\"(?&amp;lt;order_id&amp;gt;[^\\\"]+)"
...&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 22 Dec 2021 17:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579124#M201818</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-22T17:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Extract fields from non-JSON formatted data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579165#M201834</link>
      <description>&lt;P&gt;Hi richgalloway, Thanks for you reply.&lt;/P&gt;&lt;P&gt;Unfortunately when I for example try to table the results I do not receive any results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Base search ....
| rex "order_id\\\":\s\\\"(?&amp;lt;order_id&amp;gt;[^\\\"]+)"
| table order_id&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 23 Dec 2021 08:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579165#M201834</guid>
      <dc:creator>Matthew86</dc:creator>
      <dc:date>2021-12-23T08:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Extract fields from non-JSON formatted data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579166#M201835</link>
      <description>&lt;P&gt;fixed it:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=line.message "order_id\\\":\s\\\"(?&amp;lt;order_id&amp;gt;[^\\\"]+)"
| table order_id&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 23 Dec 2021 08:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-fields-from-non-JSON-formatted-data/m-p/579166#M201835</guid>
      <dc:creator>Matthew86</dc:creator>
      <dc:date>2021-12-23T08:49:05Z</dc:date>
    </item>
  </channel>
</rss>

