<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regular expression for json in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593185#M206469</link>
    <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 09 Apr 2022 09:03:26 GMT</pubDate>
    <dc:creator>chvenu17</dc:creator>
    <dc:date>2022-04-09T09:03:26Z</dc:date>
    <item>
      <title>Help with Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593172#M206460</link>
      <description>&lt;P&gt;I need regular expression to extract JSON from message field .. Can some one help&lt;/P&gt;
&lt;P&gt;After extract i want to parse the extracted json using spath command&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;{ [-]&lt;BR /&gt;@timestamp: 2022-04-09T05:50:04.336Z&lt;BR /&gt;@version: 1&lt;BR /&gt;file: test.log&lt;BR /&gt;message: 2021-04-09 05:50:04.273+0000 INFO |RestAPI.adminsrvr | Request #5172: {&lt;BR /&gt;"context": {&lt;BR /&gt;"httpContextKey": 1111111111,&lt;BR /&gt;"verbId": 2,&lt;BR /&gt;"verb": "GET",&lt;BR /&gt;"originalVerb": "GET",&lt;BR /&gt;"protocol": "https",&lt;BR /&gt;"parameters": {&lt;BR /&gt;"uri": {&lt;BR /&gt;"version": "v2"&lt;BR /&gt;}}}}&lt;BR /&gt;name: test&lt;BR /&gt;no: 111111111111&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 15:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593172#M206460</guid>
      <dc:creator>chvenu17</dc:creator>
      <dc:date>2022-04-11T15:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593174#M206461</link>
      <description>&lt;P&gt;This assumes that the message field is immediately followed by name&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?ms)message:.+?(?&amp;lt;json&amp;gt;\{.*\})\s*name&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 07:20:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593174#M206461</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-04-09T07:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593176#M206462</link>
      <description>&lt;P&gt;Thanks for immediate response&lt;/P&gt;&lt;P&gt;Name is another field&lt;/P&gt;&lt;P&gt;The "message" field contains below sample data ..it just ends with JSON object.&lt;/P&gt;&lt;P&gt;I need to extract json and create new field&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;message: 2021-04-09 05:50:04.273+0000 INFO |RestAPI.adminsrvr | Request #5172: {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"context": {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"httpContextKey": 1111111111,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"verbId": 2,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"verb": "GET",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"originalVerb": "GET",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"protocol": "https",&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"parameters": {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"uri": {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"version": "v2"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}}}}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 07:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593176#M206462</guid>
      <dc:creator>chvenu17</dc:creator>
      <dc:date>2022-04-09T07:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593177#M206463</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "(?ms)message:.+?(?&amp;lt;json&amp;gt;\{.*\})\s*name"&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 09 Apr 2022 07:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593177#M206463</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-04-09T07:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593178#M206464</link>
      <description>&lt;P&gt;Not getting, just getting empty output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?ms)message:.+?(?&amp;lt;json&amp;gt;\{.*\})\s*name" |table json&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 09 Apr 2022 07:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593178#M206464</guid>
      <dc:creator>chvenu17</dc:creator>
      <dc:date>2022-04-09T07:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593180#M206465</link>
      <description>&lt;P&gt;The below rex giving&amp;nbsp; "{" as output ( the start of json)..Need to tweak to print&amp;nbsp; to the end&lt;/P&gt;&lt;P&gt;|table message&lt;BR /&gt;| rex field=message "Request \#[0-9]+\: (?&amp;lt;json&amp;gt;.+)" |table json&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 08:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593180#M206465</guid>
      <dc:creator>chvenu17</dc:creator>
      <dc:date>2022-04-09T08:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593181#M206466</link>
      <description>&lt;P&gt;Try with the ms flags so that . will match across new lines&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=message "(?ms)Request \#[0-9]+\: (?&amp;lt;json&amp;gt;.+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 09 Apr 2022 08:36:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593181#M206466</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-04-09T08:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593182#M206467</link>
      <description>&lt;P&gt;it perfectly worked. What does (?ms) represents here . Can you explain&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 08:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593182#M206467</guid>
      <dc:creator>chvenu17</dc:creator>
      <dc:date>2022-04-09T08:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593184#M206468</link>
      <description>&lt;P&gt;m - means multiline&lt;/P&gt;&lt;P&gt;s - means . will match to new line - this is actually the important one in this instance&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=message "(?s)Request \#[0-9]+\: (?&amp;lt;json&amp;gt;.+)"&lt;/LI-CODE&gt;&lt;P&gt;This should also work for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 08:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593184#M206468</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-04-09T08:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593185#M206469</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 09:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/593185#M206469</guid>
      <dc:creator>chvenu17</dc:creator>
      <dc:date>2022-04-09T09:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Regular expression for json</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/676783#M231449</link>
      <description>&lt;P&gt;i have my json data where sometimes we are unable to see the status: closed field in some of the events as i want to write a regex to bring this in event&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;state&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" title="" href="https://thehartford.splunkcloud.com/en-US/app/search/search?s=%2FservicesNS%2Fnobody%2Fsearch%2Fsaved%2Fsearches%2FOrca%2520High%2520Alert&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;q=search%20index%3D%22orca%22%20%7C%20spath%20category%20%7C%20search%20category!%3DVulnerabilities%20%7C%20spath%20%22state.risk_level%22%3Dhigh%20%7C%20spath%20category%20%7C%20search%20category!%3D%22IAM%20misconfigurations%22%7C%20spath%20category%20%7C%20search%20category!%3DAuthentication%20%7C%20search%20ECOCESandbox%20%20%7C%20rex%20field%3D%22status%3A%22%20%22(%3Fms)closed%20%5C%23%5Ba-z%5D%2B%5C%3A%20(%3F%3Cjson%3E.%2B)%22&amp;amp;earliest=-30d%40d&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1707259466.2784654_23343E85-AC37-41EB-B1E0-3F3897BE572B#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;alert_id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;orca-8452634&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;closed_reason&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;closed_time&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;created_at&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2023-07-06T11:41:18+00:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;high_since&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;in_verification&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;is_new_score&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;last_seen&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2024-02-04T11:38:11+00:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;last_updated&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2024-02-05T13:45:45+00:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;low_since&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2024-02-05T13:45:45+00:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;orca_score&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;7&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;risk_level&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;high&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;rule_source&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;score&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;severity&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;imminent compromise&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;status&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;closed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;status_time&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2024-02-05T13:45:45+00:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;verification_status&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;null&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help us to close this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 22:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Regular-expression-for-json/m-p/676783#M231449</guid>
      <dc:creator>senthild</dc:creator>
      <dc:date>2024-02-06T22:59:46Z</dc:date>
    </item>
  </channel>
</rss>

