<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capturing Multiple values in single group via regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612504#M212959</link>
    <description>&lt;P&gt;The ellipsis (...) were to indicate the rest of your command - try it like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=3 "(?&amp;lt;Par&amp;gt;P[1-9][0-9]*)"&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 09 Sep 2022 05:31:35 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-09-09T05:31:35Z</dc:date>
    <item>
      <title>How to capture Multiple values in single group via regex?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612457#M212944</link>
      <description>&lt;P&gt;Need to extract P302 P1 P2 with a single regular ex I build&amp;nbsp;(?&amp;lt;Par&amp;gt;P[1-9][0-9]*) but when I run this in splunk it only captures first (P302)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;[SearchBroker - XXX] - [submitSearch] INFO: XXX [] - submitSearch time=36 pTime={P302=11,P1=7,P301=13,P2=24,P3=23,P4=31,P5=25,P6=23,P300=13,P7=23,P8=24,P9=24,P10=21,P12=24,P11=23,P1000=1,P14=26,P13=24,P16=21,P15=20,P18=20,P17=23} pProcessTime={P302p=10,P1p=6,P301p=12,P2p=23,P3p=22,P4p=30,P5p=24,P6p=23,P300p=13,P7p=23,P8p=24,P9p=24,P10p=21,P12p=23,P11p=22,P1000p=0,P14p=26,P13p=23,P16p=20,P15p=20,P18p=20,P17p=23} pWaitTime=&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 01:29:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612457#M212944</guid>
      <dc:creator>abhishekbhasin</dc:creator>
      <dc:date>2022-09-09T01:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing Multiple values in single group via regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612461#M212946</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex max_match=3 ...&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 08 Sep 2022 18:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612461#M212946</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-08T18:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing Multiple values in single group via regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612465#M212947</link>
      <description>&lt;P&gt;Full syntax please&amp;nbsp;rex max_match=3 ...&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;(?&amp;lt;Par&amp;gt;P[1-9][0-9]*) doesn't work&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 18:50:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612465#M212947</guid>
      <dc:creator>abhishekbhasin</dc:creator>
      <dc:date>2022-09-08T18:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing Multiple values in single group via regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612475#M212953</link>
      <description>&lt;P&gt;Can you explain "doesn't work?" &amp;nbsp;This is a test:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = " [SearchBroker - XXX] - [submitSearch] INFO: XXX [] - submitSearch time=36 pTime={P302=11,P1=7,P301=13,P2=24,P3=23,P4=31,P5=25,P6=23,P300=13,P7=23,P8=24,P9=24,P10=21,P12=24,P11=23,P1000=1,P14=26,P13=24,P16=21,P15=20,P18=20,P17=23} pProcessTime={P302p=10,P1p=6,P301p=12,P2p=23,P3p=22,P4p=30,P5p=24,P6p=23,P300p=13,P7p=23,P8p=24,P9p=24,P10p=21,P12p=23,P11p=22,P1000p=0,P14p=26,P13p=23,P16p=20,P15p=20,P18p=20,P17p=23} pWaitTime="
| rex max_match=3 "(?&amp;lt;Par&amp;gt;P[1-9][0-9]*)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output is exactly 3 values in Par.&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;Par&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;_raw&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;P302&lt;/DIV&gt;&lt;DIV class=""&gt;P1&lt;/DIV&gt;&lt;DIV class=""&gt;P301&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;[SearchBroker - XXX] - [submitSearch] INFO: XXX [] - submitSearch time=36 pTime={P302=11,P1=7,P301=13,P2=24,P3=23,P4=31,P5=25,P6=23,P300=13,P7=23,P8=24,P9=24,P10=21,P12=24,P11=23,P1000=1,P14=26,P13=24,P16=21,P15=20,P18=20,P17=23} pProcessTime={P302p=10,P1p=6,P301p=12,P2p=23,P3p=22,P4p=30,P5p=24,P6p=23,P300p=13,P7p=23,P8p=24,P9p=24,P10p=21,P12p=23,P11p=22,P1000p=0,P14p=26,P13p=23,P16p=20,P15p=20,P18p=20,P17p=23} pWaitTime=&lt;/TD&gt;&lt;TD&gt;2022-09-08 20:42:37&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Maybe you need all of them? &amp;nbsp;Then max_match=0.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 20:45:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612475#M212953</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-09-08T20:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing Multiple values in single group via regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612504#M212959</link>
      <description>&lt;P&gt;The ellipsis (...) were to indicate the rest of your command - try it like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=3 "(?&amp;lt;Par&amp;gt;P[1-9][0-9]*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 09 Sep 2022 05:31:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612504#M212959</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-09T05:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Capturing Multiple values in single group via regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612560#M212979</link>
      <description>&lt;P&gt;Thanks!. It works&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 11:45:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-capture-Multiple-values-in-single-group-via-regex/m-p/612560#M212979</guid>
      <dc:creator>abhishekbhasin</dc:creator>
      <dc:date>2022-09-09T11:45:53Z</dc:date>
    </item>
  </channel>
</rss>

