<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract Multiple fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589057#M205146</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jayeshrajvir_0-1647344653392.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18505i00873F2B99D74DF2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jayeshrajvir_0-1647344653392.png" alt="jayeshrajvir_0-1647344653392.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/137142"&gt;@venky1544&lt;/a&gt;&amp;nbsp;It fetches/matching all the four fields. I wanted to match only two fields. Can you please share your thoughts.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Mar 2022 11:45:40 GMT</pubDate>
    <dc:creator>jayeshrajvir</dc:creator>
    <dc:date>2022-03-15T11:45:40Z</dc:date>
    <item>
      <title>Extract Multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589041#M205137</link>
      <description>&lt;P&gt;Sample data&lt;/P&gt;&lt;P&gt;[A028 : 00]&lt;BR /&gt;[F037 : 928323177452]&lt;BR /&gt;[F038 : 456137]&lt;BR /&gt;[F039 : 0]&lt;/P&gt;&lt;P&gt;The query below is working but i wanted to merge, basically i wanted to use&amp;nbsp;rex field=_raw just once. How to extract multiple fields&lt;/P&gt;&lt;P&gt;index=au_axs_common_log sourcetype=anz_axs_auth_core_log "[A028" |rex field=_raw "(\[F039\s*:(?.*?)\])"| rex field=_raw "\[A028\s*:(?.*?)\]" |stats count by axrc,vrc&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 09:32:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589041#M205137</guid>
      <dc:creator>jayeshrajvir</dc:creator>
      <dc:date>2022-03-15T09:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Extract Multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589045#M205141</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243602"&gt;@jayeshrajvir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try this regex&amp;nbsp;\[\w+\s:\s\d+\]&lt;/P&gt;&lt;P&gt;just curious what are you doing with the regex coz there is no named group in the regex&amp;nbsp; ??&lt;/P&gt;&lt;P&gt;is this a tweaked query you pasted here&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 09:48:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589045#M205141</guid>
      <dc:creator>venky1544</dc:creator>
      <dc:date>2022-03-15T09:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Extract Multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589057#M205146</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jayeshrajvir_0-1647344653392.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18505i00873F2B99D74DF2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jayeshrajvir_0-1647344653392.png" alt="jayeshrajvir_0-1647344653392.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/137142"&gt;@venky1544&lt;/a&gt;&amp;nbsp;It fetches/matching all the four fields. I wanted to match only two fields. Can you please share your thoughts.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 11:45:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589057#M205146</guid>
      <dc:creator>jayeshrajvir</dc:creator>
      <dc:date>2022-03-15T11:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Extract Multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589080#M205153</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243602"&gt;@jayeshrajvir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PFB screenshot hope this helps&amp;nbsp;&lt;/P&gt;&lt;P&gt;| makeresults |eval new = "[A028 : 00]"&lt;BR /&gt;|append [|makeresults |eval new="[F037 : 928323177452]"]&lt;BR /&gt;|append [|makeresults |eval new="[F038 : 456137]"]&lt;BR /&gt;|append [|makeresults |eval new="[F039 : 0]"]&lt;BR /&gt;|rex field=new "(\[A028|\[F038)\s:\s(?&amp;lt;num&amp;gt;\d+)\]"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venky1544_0-1647348590034.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18512i2903912BD1E33BB2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venky1544_0-1647348590034.png" alt="venky1544_0-1647348590034.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 12:50:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-Multiple-fields/m-p/589080#M205153</guid>
      <dc:creator>venky1544</dc:creator>
      <dc:date>2022-03-15T12:50:28Z</dc:date>
    </item>
  </channel>
</rss>

