<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What would be the regular expression when using rex to match fields that end with a range of values? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-would-be-the-regular-expression-when-using-rex-to-match/m-p/614470#M213554</link>
    <description>&lt;P&gt;What would be the regular expression when using rex to match fields that end with a range of values?&lt;/P&gt;
&lt;P&gt;Sample:&lt;BR /&gt;"var0":0,"var1":10,"var2":20,"var10":100&lt;BR /&gt;&lt;BR /&gt;I would like to extract fields from var1 to var10, and &lt;STRONG&gt;exclude&amp;nbsp;&lt;/STRONG&gt;var0.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 15:25:13 GMT</pubDate>
    <dc:creator>dzyfer</dc:creator>
    <dc:date>2022-09-26T15:25:13Z</dc:date>
    <item>
      <title>What would be the regular expression when using rex to match fields that end with a range of values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-would-be-the-regular-expression-when-using-rex-to-match/m-p/614470#M213554</link>
      <description>&lt;P&gt;What would be the regular expression when using rex to match fields that end with a range of values?&lt;/P&gt;
&lt;P&gt;Sample:&lt;BR /&gt;"var0":0,"var1":10,"var2":20,"var10":100&lt;BR /&gt;&lt;BR /&gt;I would like to extract fields from var1 to var10, and &lt;STRONG&gt;exclude&amp;nbsp;&lt;/STRONG&gt;var0.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 15:25:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-would-be-the-regular-expression-when-using-rex-to-match/m-p/614470#M213554</guid>
      <dc:creator>dzyfer</dc:creator>
      <dc:date>2022-09-26T15:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Using rex to match range of digits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-would-be-the-regular-expression-when-using-rex-to-match/m-p/614474#M213555</link>
      <description>&lt;P&gt;Regex is not needed for this kind of format; &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Extract" target="_blank" rel="noopener"&gt;extract&lt;/A&gt;, aka kv, is sufficient. &amp;nbsp;If this is in _raw, simply do&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| kv kvdelim=":" pairdlim=","&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;If it is in a field named "data", you can do&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename _raw AS temp, data AS _raw
| kv kvdelim=":" pairdlim=","​
| rename _raw as data, temp AS _raw&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 26 Sep 2022 04:39:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-would-be-the-regular-expression-when-using-rex-to-match/m-p/614474#M213555</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-09-26T04:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Using rex to match range of digits</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-would-be-the-regular-expression-when-using-rex-to-match/m-p/614475#M213556</link>
      <description>&lt;P&gt;A search time extraction if extract does not do what you want is (from rex statement onwards - first two lines create your sample)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="\"var0\":0,\"var1\":10,\"var2\":20,\"var10\":100"
| rex max_match=0 "\"(?&amp;lt;key&amp;gt;var[1-9]\d*)\":(?&amp;lt;value&amp;gt;[^,]*)"
| foreach 0 1 2 3 4 5 6 7 8 9 [ eval k=mvindex(key, &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;), v=mvindex(value, &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;), {k}=v ]
| fields - key value k v&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 05:06:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-would-be-the-regular-expression-when-using-rex-to-match/m-p/614475#M213556</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-09-26T05:06:08Z</dc:date>
    </item>
  </channel>
</rss>

