<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rex for multiple fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600620#M209072</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241633"&gt;@Veeru&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can you try as following:&lt;BR /&gt;| eval GB=round(b/1024/1024/1024, 3)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 05 Jun 2022 17:40:27 GMT</pubDate>
    <dc:creator>Roy_9</dc:creator>
    <dc:date>2022-06-05T17:40:27Z</dc:date>
    <item>
      <title>How to create rex for multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600618#M209071</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;Good Day!&lt;BR /&gt;I have the events in the raw data where i want to extract the drive information&amp;nbsp; into few field and convert into gb&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;event1:C:\Windows\system FreeSpace DeviceID FreeSpace&lt;BR /&gt;C: 36247773184&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; 96900616192&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;E: 26285309952&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;event2:C:\Windows\system DeviceID FreeSpace&lt;BR /&gt;C: 36247773184&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; 96900616192&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;event3:C:\Windows\system DeviceID FreeSpace&lt;BR /&gt;C: 36247773184&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;event4:C: 36247773184&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; 96900616192&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;E: 26285309952&lt;BR /&gt;&lt;BR /&gt;My Query:&lt;BR /&gt;index=A&lt;BR /&gt;|rex "(?&amp;lt;Drive&amp;gt;\S+:\s+\d+)"&lt;BR /&gt;|stats values(Drive) by host _raw&lt;BR /&gt;&lt;BR /&gt;My output:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;Host&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;_raw&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Drive&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;A1&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;
&lt;P&gt;&lt;SPAN&gt;C:\Windows\system FreeSpace DeviceID FreeSpace&lt;BR /&gt;C: 36247773184&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; 96900616192&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;E: 26285309952&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;&lt;SPAN&gt;C: 36247773184&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;A2&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;
&lt;P&gt;&lt;SPAN&gt;C:\Windows\system FreeSpace DeviceID FreeSpace&lt;BR /&gt;C: 36247773184&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; 96900616192&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;&lt;SPAN&gt;C: 36247773184&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;I am getting only first values .But i want to get a the values from the raw event and want to convert the digital value into gb&lt;BR /&gt;Please help me on that&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;BR /&gt;Veeru&lt;BR /&gt;&lt;BR /&gt;"Happy Splunking"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 03:50:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600618#M209071</guid>
      <dc:creator>Veeru</dc:creator>
      <dc:date>2022-06-06T03:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rex for multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600620#M209072</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241633"&gt;@Veeru&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can you try as following:&lt;BR /&gt;| eval GB=round(b/1024/1024/1024, 3)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 17:40:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600620#M209072</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2022-06-05T17:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Rex for multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600621#M209073</link>
      <description>&lt;P&gt;You can match multiple times with max_match option for the rex command.&lt;/P&gt;&lt;PRE&gt;| rex max_match=0 "(?&amp;lt;Drive&amp;gt;..."&lt;/PRE&gt;</description>
      <pubDate>Sun, 05 Jun 2022 17:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600621#M209073</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-06-05T17:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rex for multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600622#M209074</link>
      <description>&lt;LI-CODE lang="markup"&gt;|rex max_match=0 "(?&amp;lt;Drive&amp;gt;\S+):\s+(?&amp;lt;size&amp;gt;\d+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 05 Jun 2022 17:44:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-for-multiple-fields/m-p/600622#M209074</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-06-05T17:44:52Z</dc:date>
    </item>
  </channel>
</rss>

