<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REX Field Help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588814#M205056</link>
    <description>&lt;P&gt;Much appreciated mate for your help!. It worked for me.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2022 20:21:48 GMT</pubDate>
    <dc:creator>kc_prane</dc:creator>
    <dc:date>2022-03-11T20:21:48Z</dc:date>
    <item>
      <title>How to get fields extracted by two fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588772#M205043</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;i need&amp;nbsp; the fields&amp;nbsp; extracted&amp;nbsp; by two fields&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;1) Detail message&amp;nbsp; = before the comma ( I need the full description)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;2) Count =&amp;nbsp; after the comma ( I need the digit count)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;RAW Log starts from below :&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;DETAIL MESSAGE, COUNT

Index 0 out of bounds for length 0, 61

No Recipienet found in MDM based on the input parameters, 120

No record found with this document Id, 86

No Records Found with given search Criteria in DB, 52

query did not return a unique result: 2; nested exception is javax.persistence.NonUniqueResultException: query did not return a unique result: 2, 106&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN class=""&gt;You&lt;/SPAN&gt; &lt;SPAN class=""&gt;do&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;currently&lt;/SPAN&gt; &lt;SPAN class=""&gt;manage&lt;/SPAN&gt; &lt;SPAN class=""&gt;any&lt;/SPAN&gt; &lt;SPAN class=""&gt;user&lt;/SPAN&gt; &lt;SPAN class=""&gt;roles&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;PERLSS&lt;/SPAN&gt; &lt;SPAN class=""&gt;there&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;no&lt;/SPAN&gt; &lt;SPAN class=""&gt;task&lt;/SPAN&gt; &lt;SPAN class=""&gt;data&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;display&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;this&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;96&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 05:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588772#M205043</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2022-03-12T05:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: REX Field Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588783#M205046</link>
      <description>&lt;P&gt;This should get you started&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?&amp;lt;detailMessage&amp;gt;[^,]+), (?&amp;lt;count&amp;gt;\d+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 11 Mar 2022 17:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588783#M205046</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-11T17:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: REX Field Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588792#M205048</link>
      <description>&lt;P&gt;Thanks, @&lt;SPAN&gt;richgalloway. But here I am only getting the first line for the fields extracted&amp;nbsp; in the log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kc_prane_0-1647023504759.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18463i39C2912A063D38DE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kc_prane_0-1647023504759.png" alt="kc_prane_0-1647023504759.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 18:34:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588792#M205048</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2022-03-11T18:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: REX Field Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588804#M205052</link>
      <description>&lt;P&gt;You say you only get one line, but the screenshot shows 7 lines.&lt;/P&gt;&lt;P&gt;Please provide more information, including the query used and the props.conf settings for the sourcetype.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 19:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588804#M205052</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-11T19:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: REX Field Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588809#M205053</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; &amp;nbsp;I don't have much details of the props but the below screenshot shows the rex is working only for the first line.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kc_prane_0-1647028953208.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18467i1FFBE67669624A55/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kc_prane_0-1647028953208.png" alt="kc_prane_0-1647028953208.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 20:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588809#M205053</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2022-03-11T20:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: REX Field Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588813#M205055</link>
      <description>&lt;P&gt;It was not clear from the OP that the sample data was a single event rather than multiple events.&amp;nbsp; That means the regular expression matches multiple strings, but the &lt;FONT face="courier new,courier"&gt;rex&lt;/FONT&gt; command defaults to returning only the first.&amp;nbsp; Use the &lt;FONT face="courier new,courier"&gt;max_match&lt;/FONT&gt; option to override that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=0 "(?&amp;lt;detailMessage&amp;gt;[^,]+), (?&amp;lt;count&amp;gt;\d+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will produce multi-value fields. You'll then need to use mv commands/functions to work with the fields.&lt;/P&gt;&lt;P&gt;Let us know what results you want and we can try to be more specific.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 20:23:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588813#M205055</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-11T20:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: REX Field Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588814#M205056</link>
      <description>&lt;P&gt;Much appreciated mate for your help!. It worked for me.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 20:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-fields-extracted-by-two-fields/m-p/588814#M205056</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2022-03-11T20:21:48Z</dc:date>
    </item>
  </channel>
</rss>

