<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract data from log message data using rex field=_raw? Sample data is in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614488#M213566</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for your response means a lot.&lt;/P&gt;&lt;PRE&gt;| rex "(?ms)Instance\s+Name\s+:\s+(?&amp;lt;Instance_Name&amp;gt;\w+).*Uptime\s+(?&amp;lt;Uptime&amp;gt;.+)Listening"&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;using this regex help me extract the Instance_Name only in the correct format.&lt;BR /&gt;for uptime I am receiving output as below&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4 days 6 hr. 39 min. 25 sec&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Listening Endpoints Summary...&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=113.09.126.234)(PORT=12345)))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC12345)))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The command completed successfully&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Instance Name : ABCDEFGH1TEMP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Instance Name : ABCDEFGQ1&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I also have to extract the Alias name&lt;BR /&gt;I tried using&amp;nbsp;| rex "Alias\s+(?&amp;lt;Alias)&amp;gt;.+)"&amp;nbsp; &amp;nbsp;for this I am getting below mentioned error.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Error in 'rex' command: Encountered the following error while compiling the regex 'Alias\s+(?&amp;lt;Alias)&amp;gt;.+)': Regex: syntax error in subpattern name (missing terminator).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Please assist me on the same.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 06:57:49 GMT</pubDate>
    <dc:creator>AK_Splunk</dc:creator>
    <dc:date>2022-09-26T06:57:49Z</dc:date>
    <item>
      <title>How to extract data from log message data using rex field=_raw? Sample data is</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614476#M213557</link>
      <description>&lt;P&gt;How to extract data from log message data using rex field=_raw? Sample data is&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Instance Name : ABCDEFGH1&lt;BR /&gt;Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=ampxwdp1o.pharma.aventis.com)(PORT=12345)))&lt;BR /&gt;Alias ABCDEFGH1&lt;BR /&gt;Uptime 4 days 6 hr. 39 min. 25 sec&lt;BR /&gt;Listening Endpoints Summary...&lt;BR /&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=113.09.126.234)(PORT=12345)))&lt;BR /&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC12345)))&lt;BR /&gt;The command completed successfully&lt;BR /&gt;Instance Name : ABCDEFGH1TEMP&lt;BR /&gt;Instance Name : ABCDEFGQ1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I need to extract Instance name, Alias Uptime&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 05:37:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614476#M213557</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2022-09-26T05:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data from log message data using rex field=_raw? Sample data is</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614484#M213562</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you want to extract all the Instance Names present in your logs, you have to use two different regexes:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "Instance\s+Name\s+:\s+(?&amp;lt;Instance_Name&amp;gt;\w+)"
| rex "Uptime\s+(?&amp;lt;Uptime)&amp;gt;.+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&lt;A href="https://regex101.com/r/vPWiOh/2" target="_blank"&gt;https://regex101.com/r/vPWiOh/2&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://regex101.com/r/vPWiOh/3" target="_blank"&gt;https://regex101.com/r/vPWiOh/3&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If instead you want to extract only the first Instance name, you can use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?ms)Instance\s+Name\s+:\s+(?&amp;lt;Instance_Name&amp;gt;\w+).*Uptime\s+(?&amp;lt;Uptime&amp;gt;.+)Listening"&lt;/LI-CODE&gt;&lt;P&gt;You can test this regex at &lt;A href="https://regex101.com/r/vPWiOh/1" target="_blank"&gt;https://regex101.com/r/vPWiOh/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Anyway,&amp;nbsp;you don't need to add field=_raw when you're searching on all the raw event.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 06:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614484#M213562</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-26T06:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data from log message data using rex field=_raw? Sample data is</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614488#M213566</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for your response means a lot.&lt;/P&gt;&lt;PRE&gt;| rex "(?ms)Instance\s+Name\s+:\s+(?&amp;lt;Instance_Name&amp;gt;\w+).*Uptime\s+(?&amp;lt;Uptime&amp;gt;.+)Listening"&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;using this regex help me extract the Instance_Name only in the correct format.&lt;BR /&gt;for uptime I am receiving output as below&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4 days 6 hr. 39 min. 25 sec&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Listening Endpoints Summary...&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=113.09.126.234)(PORT=12345)))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC12345)))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The command completed successfully&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Instance Name : ABCDEFGH1TEMP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Instance Name : ABCDEFGQ1&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I also have to extract the Alias name&lt;BR /&gt;I tried using&amp;nbsp;| rex "Alias\s+(?&amp;lt;Alias)&amp;gt;.+)"&amp;nbsp; &amp;nbsp;for this I am getting below mentioned error.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Error in 'rex' command: Encountered the following error while compiling the regex 'Alias\s+(?&amp;lt;Alias)&amp;gt;.+)': Regex: syntax error in subpattern name (missing terminator).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Please assist me on the same.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 06:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614488#M213566</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2022-09-26T06:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data from log message data using rex field=_raw? Sample data is</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614490#M213567</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;abou the output you're receiving, in regex101 it correctly runs, I don't know why you the this output instead teh correct one, maybe try to use this, but it should be the same thig:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?ms)Instance\s+Name\s+:\s+(?&amp;lt;Instance_Name&amp;gt;\w+).*Uptime\s+(?&amp;lt;Uptime&amp;gt;.+)Listening Endpoints Summary"&lt;/LI-CODE&gt;&lt;P&gt;About the alias, I don't see any alias word in your logs and there's a wrong parethesis in the field name:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Alias\s+(?&amp;lt;Alias&lt;FONT color="#FF0000"&gt;)&lt;/FONT&gt;&amp;gt;.+)"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 07:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614490#M213567</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-26T07:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data from log message data using rex field=_raw? Sample data is</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614491#M213568</link>
      <description>&lt;P&gt;&lt;SPAN&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks for your response&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The third line has alias feild&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Instance Name : ABCDEFGH1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=TCP)(HOST=ampxwdp1o.pharma.aventis.com)(PORT=12345)))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alias ABCDEFGH1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Uptime 4 days 6 hr. 39 min. 25 sec&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Listening Endpoints Summary...&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=113.09.126.234)(PORT=12345)))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC12345)))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The command completed successfully&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Instance Name : ABCDEFGH1TEMP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Instance Name : ABCDEFGQ1&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 07:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614491#M213568</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2022-09-26T07:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract data from log message data using rex field=_raw? Sample data is</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614513#M213572</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, I don't know how I did to not see it!&lt;/P&gt;&lt;P&gt;Anyway, please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "Alias\s+(?&amp;lt;Alias&amp;gt;\w+)"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 08:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-log-message-data-using-rex-field-raw/m-p/614513#M213572</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-26T08:41:21Z</dc:date>
    </item>
  </channel>
</rss>

