<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with REX command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611409#M212582</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49880"&gt;@mdyunusraza&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is a json log so did you tried the spath command (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath&lt;/A&gt;) to extract fields?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Aug 2022 06:04:42 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-08-31T06:04:42Z</dc:date>
    <item>
      <title>Help with REX command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611407#M212580</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I want to create a table from the sample log file entry by computing the field names based on the entries defined in the JSON structure. There will be multiple filed names and not just one.&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g. in, the JSON structure, it has entries like&amp;nbsp;&lt;STRONG&gt;"something"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"value"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;STRONG&gt;something&lt;/STRONG&gt;" will be the &lt;EM&gt;field name&lt;/EM&gt;, and "&lt;STRONG&gt;value&lt;/STRONG&gt;" will be the &lt;EM&gt;value&lt;/EM&gt; that will form the table entries.&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;By working in&amp;nbsp;&lt;A href="https://regex101.com" target="_blank" rel="noopener"&gt;https://regex101.com&lt;/A&gt;&amp;nbsp;I have got the regex query that is doing the job. However, when I try to put that in the Splunk search query, it does not like the "]" in the regex query I have generated.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;This is the regex query:&amp;nbsp;&lt;STRONG&gt;"((?:[^"\\\/\b\f\n\r\t]|\\u\d{4})*)"&lt;/STRONG&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;Query in Splunk&amp;nbsp; &lt;STRONG&gt;| rex "((?:[^"\\\/\b\f\n\r\t]|\\u\d{4})*)"&lt;/STRONG&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;Error in Splunk : &lt;STRONG&gt;Error in 'SearchParser': Mismatched ']'.&lt;/STRONG&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;This is the sample log:&lt;/P&gt;&lt;P data-unlink="true"&gt;-------------------&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;BR /&gt;2022/08/31 04:33:10.897 | server| service| INFO | 1-223 |x.x.x.x.x.Payload | xxx-1111-1111111-11-111111111 | AAt: Update Headers: {AAgid=ID:jaaana-11111-1111111111111-3:487:1:1:50, cccc_ff_ssss=ABC_XYZ, ssssdel=false, cdmode=1, DelMode=2, abc_corel_id=xyx-11111-11111-11-111111, aa_rrr_cccc_cccc=AAAA, cust_svc_id=AAAA-DDD, crumberid=xyx-11111-11111-11-111111, svc_tran_origin=SSS, SSScoreed=Camel-SSS-1111-1111111-111, cccc_ff_ssss_aaaaa=AAAA, AAAType=null, cccc_ff_ssss_tata=AAA, AAAexxxx=0, avronnnn=url.add.add.com, AAAssssssss=1661920390882,tang_dik_jagah=ABC_XYZ, ver=0.1.2, AAAprrrrrr=4, AAArptooo=null, source_DOT_adaptr=mom, AAAjaaana=tAAic://toic,tang_dik_jagah_tata=AAA, targCTService=progr, SSScoreedAsBytes=[a@123, CamelAAARequestTimeout=600000, sedaTimeout=600000} {[{"type":"AAtiongo","pAAo":"AAAA","ssssssss":"2022-08-31 00:00:00","data":[{"chabbbi":"ca_1111_11111_AAtiongo_AAAA","tatajahajqaki":"AA 111","jahajqaki":{"numeo":"111","jahaaj":{"cde":"ARL_AA","couAAa":"AA","aaoo":"AAR"},"AAsuf":null},"sgnnnn":"AAR111","stppp":"J","muddStatuscde":"AA","kissak":"III","AAType3lc":"111","AAType5lc":"B111","rggggggg":"AAAAA","carrrrr":{"cde":"ARL_AA","couAAa":"AA","aaoo":"AAR"},"ddddddcde":"pubbb","pubbbjahajqaki":"AA 111","jahajqakipubbb":{"numeo":"111","jahaaj":{"cde":"AA","couAAa":null,"aaoo":null}},"sssss":1098,"kkkkkss":834,"kitnaba":{"AAAAAA":"2022-08-2100:00:00","WWWW":"2022-08-2100:00:00","eeeeee":"2022-08-2100:00:00","sssssss":"2022-08-2100:00:00","ddddddd":"2022-08-2100:00:00","eeeeeeee":"2022-08-2100:00:00","ddddddddd":"2022-08-2100:00:00","ttttttt":"2022-08-2100:00:00","ttttttt":"2022-08-2100:00:00","Edddddd":"2022-08-2100:00:00","ffffff":"2022-08-2100:00:00","ddddddL":"2022-08-2100:00:00","dddddd":"2022-08-2100:00:00","Adddddd":"2022-08-2100:00:00","ssssT":"2022-08-2100:00:00","ddddd":"2022-08-2100:00:00","ggggg":"2022-08-2100:00:00","ffffff":"2022-08-2100:00:00","Eddddd":"2022-08-2100:00:00","ssssss":"2022-08-2100:00:00","Eddddd":"2022-08-2100:00:00"},"durdddd":{"Exxxxx":"Pdddd.oo","ScfffTTTT":"xxx1H0M0.000S","xxxxIDL":"-Pxxxx6M0.000S","ESTTTT":"PxxxxH26M0.000S"},"gallle":[{"aaaaaaa":"aaa000033","gffffnnnn":"111"}],"stsssss":[{"hhhhhh":"AA1111111","standnnnn":"S20"}],"blttttt":[{"hhhhhh":"ABB000003","beltnnnn":"aa11","beltAAenpttttt":"2022-08-2100:00:00","kkkkkkkpttttt":"2022-08-2100:00:00"}],"redddddd":{"SSSSS":[{"aalllll":"ALLUU99999","resssssss":"AA1111111","resssssssnnnn":"S20","pprrrrrsssss":"AAA11111"}],"bgggg_blt":[{"aalllll":"aaaaaa1111111","resssssss":"ABB000003","resssssssnnnn":"IB02","kitnaba":{"AAAAAA":"2022-08-31006:14:00a","AAAAAA":"2022-08-31006:14:00a"}}],"aaaaaaaaaaa_sss":[{"aalllll":"aaaaaa8888888","resssssss":"false"}],"aaaaaaaaaa_ssss":[{"aalllll":"aaaaaa8888888","resssssss":"GAT000033","resssssssnnnn":"120","pprrrrrsssss":"GAT000019"}],"qqqqqqqqqqqq":[{"aalllll":"qqqqqqqqqqqq","resssssss":"false"}]},"kkkkkk":[{"cde":"aaa_sss","tatAAde":"CAI","aaaaAAde":"PPPP","legnumeo":1},{"cde":"ABC_XYZ","tatAAde":"AAA","aaaaAAde":"AAAA","legnumeo":2}],"cdeshareList":[{"numeo":"1111","jahaaj":{"cde":"ARL_AA","couAAa":"AA","aaoo":"AAA"},"AAsuf":null,"pubbbjahajqaki":"AA 1111","jahajqakipubbb":{"numeo":"1111","jahaaj":{"cde":"AA","couAAa":null,"aaoo":null}}},{"numeo":"1111","jahaaj":{"cde":"ARL_CT","couAAa":"CT","aaoo":"CTH"},"AAsuf":null,"pubbbjahajqaki":"CT 1111","jahajqakipubbb":{"numeo":"1111","jahaaj":{"cde":"CT","couAAa":null,"aaoo":null}}}],"saaaaaa":{"ffff":"RRR","mapr":"Finalised","SSSGeneral":"AAened","AAceptance":"Finalised","loddacctrr":"SheCT_Finalised","brrrrrrdd":"AAened","IIIernal":"110"}}]}]}&lt;BR /&gt;host = mucAAuplfrAA02&lt;/P&gt;&lt;P data-unlink="true"&gt;-----------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 05:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611407#M212580</guid>
      <dc:creator>mdyunusraza</dc:creator>
      <dc:date>2022-08-31T05:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help with REX command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611408#M212581</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49880"&gt;@mdyunusraza&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Try escaping those bracket symbols you are matching with a backslash.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;| rex "((?:\[^"\\\/\b\f\n\r\t\]|\\u\d{4})*)"&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 05:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611408#M212581</guid>
      <dc:creator>chaker</dc:creator>
      <dc:date>2022-08-31T05:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Help with REX command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611409#M212582</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49880"&gt;@mdyunusraza&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is a json log so did you tried the spath command (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath&lt;/A&gt;) to extract fields?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 06:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611409#M212582</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-31T06:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Help with REX command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611410#M212583</link>
      <description>&lt;P&gt;Also review the docs for the rex command. It uses named capture groups for the extracted field names.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Rex" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Rex&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 06:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611410#M212583</guid>
      <dc:creator>chaker</dc:creator>
      <dc:date>2022-08-31T06:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Help with REX command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611411#M212584</link>
      <description>&lt;P class="lia-align-left"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/165039"&gt;@chaker&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-left"&gt;Yes, I tried that, but it gives me another error, like so,&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;Error in 'SearchParser': &lt;STRONG&gt;Missing a search command before '\'.&lt;/STRONG&gt; Error at position '100' of search query 'search index=indname "service" "AAt: Upd...{snipped} &lt;STRONG&gt;{errorcontext = f\n\r\t\]|\\u\d{4})*)}'.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 06:11:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611411#M212584</guid>
      <dc:creator>mdyunusraza</dc:creator>
      <dc:date>2022-08-31T06:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help with REX command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611413#M212585</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, I have not tried that. We have used the REX command to extract fields using regex, but those were not JSON logs. We have this new log we need to dissect and form a table. Hence the requirement.&lt;/P&gt;&lt;P&gt;I will read about SPATH and see how it goes.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 06:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REX-command/m-p/611413#M212585</guid>
      <dc:creator>mdyunusraza</dc:creator>
      <dc:date>2022-08-31T06:13:23Z</dc:date>
    </item>
  </channel>
</rss>

