<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help on regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614965#M213716</link>
    <description>&lt;P&gt;hai for below example event the name need to extract after&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;user key like&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;want to extract&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;CORP\USHOU-SVC-VMWare&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;09/28/2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;06:00:00&lt;/SPAN&gt; &lt;SPAN class=""&gt;AM&lt;/SPAN&gt; &lt;SPAN class=""&gt;LogName=Microsoft-Windows-TaskScheduler/Operational&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventCode=100&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventType=4&lt;/SPAN&gt; &lt;SPAN class=""&gt;ComputerName=USHOUSSUTL01V.corp.amvescap.net&lt;/SPAN&gt; &lt;SPAN class=""&gt;User=NOT_TRANSLATED&lt;/SPAN&gt; &lt;SPAN class=""&gt;Sid=S-1-5-21-789336058-1757981266-839522115-166804&lt;/SPAN&gt; &lt;SPAN class=""&gt;SidType=0&lt;/SPAN&gt; &lt;SPAN class=""&gt;SourceName=Microsoft-Windows-TaskScheduler&lt;/SPAN&gt; &lt;SPAN class=""&gt;Type=Information&lt;/SPAN&gt; &lt;SPAN class=""&gt;RecordNumber=8012022&lt;/SPAN&gt; &lt;SPAN class=""&gt;Keywords=None&lt;/SPAN&gt; &lt;SPAN class=""&gt;TaskCategory=Task&lt;/SPAN&gt; &lt;SPAN class=""&gt;Started&lt;/SPAN&gt; &lt;SPAN class=""&gt;OpCode=Start&lt;/SPAN&gt; &lt;SPAN class=""&gt;Message=Task&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scheduler&lt;/SPAN&gt; &lt;SPAN class=""&gt;started&lt;/SPAN&gt;&lt;SPAN&gt; "{&lt;/SPAN&gt;&lt;SPAN class=""&gt;A1EB5D56-3AA0-4658-9D3D-D6642DA56541&lt;/SPAN&gt;&lt;SPAN&gt;}" &lt;/SPAN&gt;&lt;SPAN class=""&gt;instance&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;\DatastoreUsgaeReport&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;VDI&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;task&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;user&lt;/SPAN&gt; "&lt;SPAN class=""&gt;CORP\USHOU-SVC-VMWare&lt;/SPAN&gt;".&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2022 11:12:21 GMT</pubDate>
    <dc:creator>sekhar463</dc:creator>
    <dc:date>2022-09-28T11:12:21Z</dc:date>
    <item>
      <title>Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614956#M213709</link>
      <description>&lt;P&gt;Hai all,&lt;/P&gt;&lt;P&gt;Need help on to extract as new filed for user named after CORP\&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Message=Task&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scheduler&lt;/SPAN&gt; &lt;SPAN class=""&gt;started&lt;/SPAN&gt;&lt;SPAN&gt; "{&lt;/SPAN&gt;&lt;SPAN class=""&gt;B9F5A32A-A340-49C1-B620-8C7A439CA849&lt;/SPAN&gt;&lt;SPAN&gt;}" &lt;/SPAN&gt;&lt;SPAN class=""&gt;instance&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;\Microsoft\Office\OfficeTelemetryAgentFallBack&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;task&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;user&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;CORP\s-ks4&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 10:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614956#M213709</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2022-09-28T10:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614957#M213710</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "CORP\\\\(?&amp;lt;username&amp;gt;[\"]+)\""&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 28 Sep 2022 10:31:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614957#M213710</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-28T10:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614958#M213711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=Message "\"CORP\\s-(?&amp;lt;your_field&amp;gt;[^\"]+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at &lt;A href="https://regex101.com/r/cer0xU/1" target="_blank"&gt;https://regex101.com/r/cer0xU/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;this regex could be different if instead of \s there's a space after CORP.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 10:33:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614958#M213711</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-28T10:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614963#M213714</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;how to update if i want to extract after user key word the name which is present&amp;nbsp;&lt;/P&gt;&lt;P&gt;for below example event&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;09/28/2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;06:00:00&lt;/SPAN&gt; &lt;SPAN class=""&gt;AM&lt;/SPAN&gt; &lt;SPAN class=""&gt;LogName=Microsoft-Windows-TaskScheduler/Operational&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventCode=100&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventType=4&lt;/SPAN&gt; &lt;SPAN class=""&gt;ComputerName=USHOUSSUTL01V.corp.amvescap.net&lt;/SPAN&gt; &lt;SPAN class=""&gt;User=NOT_TRANSLATED&lt;/SPAN&gt; &lt;SPAN class=""&gt;Sid=S-1-5-21-789336058-1757981266-839522115-166804&lt;/SPAN&gt; &lt;SPAN class=""&gt;SidType=0&lt;/SPAN&gt; &lt;SPAN class=""&gt;SourceName=Microsoft-Windows-TaskScheduler&lt;/SPAN&gt; &lt;SPAN class=""&gt;Type=Information&lt;/SPAN&gt; &lt;SPAN class=""&gt;RecordNumber=8012022&lt;/SPAN&gt; &lt;SPAN class=""&gt;Keywords=None&lt;/SPAN&gt; &lt;SPAN class=""&gt;TaskCategory=Task&lt;/SPAN&gt; &lt;SPAN class=""&gt;Started&lt;/SPAN&gt; &lt;SPAN class=""&gt;OpCode=Start&lt;/SPAN&gt; &lt;SPAN class=""&gt;Message=Task&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scheduler&lt;/SPAN&gt; &lt;SPAN class=""&gt;started&lt;/SPAN&gt;&lt;SPAN&gt; "{&lt;/SPAN&gt;&lt;SPAN class=""&gt;A1EB5D56-3AA0-4658-9D3D-D6642DA56541&lt;/SPAN&gt;&lt;SPAN&gt;}" &lt;/SPAN&gt;&lt;SPAN class=""&gt;instance&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;\DatastoreUsgaeReport&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;VDI&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;task&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;user&lt;/SPAN&gt; "&lt;SPAN class=""&gt;CORP\USHOU-SVC-VMWare&lt;/SPAN&gt;".&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:05:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614963#M213714</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2022-09-28T11:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614965#M213716</link>
      <description>&lt;P&gt;hai for below example event the name need to extract after&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;user key like&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;want to extract&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;CORP\USHOU-SVC-VMWare&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;09/28/2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;06:00:00&lt;/SPAN&gt; &lt;SPAN class=""&gt;AM&lt;/SPAN&gt; &lt;SPAN class=""&gt;LogName=Microsoft-Windows-TaskScheduler/Operational&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventCode=100&lt;/SPAN&gt; &lt;SPAN class=""&gt;EventType=4&lt;/SPAN&gt; &lt;SPAN class=""&gt;ComputerName=USHOUSSUTL01V.corp.amvescap.net&lt;/SPAN&gt; &lt;SPAN class=""&gt;User=NOT_TRANSLATED&lt;/SPAN&gt; &lt;SPAN class=""&gt;Sid=S-1-5-21-789336058-1757981266-839522115-166804&lt;/SPAN&gt; &lt;SPAN class=""&gt;SidType=0&lt;/SPAN&gt; &lt;SPAN class=""&gt;SourceName=Microsoft-Windows-TaskScheduler&lt;/SPAN&gt; &lt;SPAN class=""&gt;Type=Information&lt;/SPAN&gt; &lt;SPAN class=""&gt;RecordNumber=8012022&lt;/SPAN&gt; &lt;SPAN class=""&gt;Keywords=None&lt;/SPAN&gt; &lt;SPAN class=""&gt;TaskCategory=Task&lt;/SPAN&gt; &lt;SPAN class=""&gt;Started&lt;/SPAN&gt; &lt;SPAN class=""&gt;OpCode=Start&lt;/SPAN&gt; &lt;SPAN class=""&gt;Message=Task&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scheduler&lt;/SPAN&gt; &lt;SPAN class=""&gt;started&lt;/SPAN&gt;&lt;SPAN&gt; "{&lt;/SPAN&gt;&lt;SPAN class=""&gt;A1EB5D56-3AA0-4658-9D3D-D6642DA56541&lt;/SPAN&gt;&lt;SPAN&gt;}" &lt;/SPAN&gt;&lt;SPAN class=""&gt;instance&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;\DatastoreUsgaeReport&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;VDI&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;task&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;user&lt;/SPAN&gt; "&lt;SPAN class=""&gt;CORP\USHOU-SVC-VMWare&lt;/SPAN&gt;".&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614965#M213716</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2022-09-28T11:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614967#M213717</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "user\s\"(?&amp;lt;username&amp;gt;[^\"]+)\""&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:19:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614967#M213717</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-28T11:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614968#M213718</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;its not working while trying in regex101&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:22:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614968#M213718</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2022-09-28T11:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614969#M213719</link>
      <description>&lt;P&gt;&lt;A href="https://regex101.com/r/AZOxz8/1" target="_blank"&gt;https://regex101.com/r/AZOxz8/1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:24:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-on-regex/m-p/614969#M213719</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-28T11:24:32Z</dc:date>
    </item>
  </channel>
</rss>

