<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk SPL in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616087#M214095</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you should explore the transpose command (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose&lt;/A&gt;) that permits to transpose a list of fields from row to column, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex field=_raw "Site\|\_\_SYSTEM\__(?&amp;lt;ServiceName&amp;gt;[A-Za-z]+)"
| rex field=_raw "Message\s\=\s(?&amp;lt;Error_Message&amp;gt;.+\:\s[A-Za-z0-9]+)"
| rex field=_raw "failed:\s(?&amp;lt;OrderNumber&amp;gt;[A-Za-z0-9]+)"
| rex field=_raw "httpStatusCode\s\=\s(?&amp;lt;ResponseTime&amp;gt;[0-9]+)"
| rex field=_raw "ResponseTime\s\=\s(?&amp;lt;Reason&amp;gt;.+)"
| table ServiceName Error_Message OrderNumber ResponseTime Reason
| transpose 5 
| rename "row 1" AS Value 
| fields Value&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 06:33:18 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-10-06T06:33:18Z</dc:date>
    <item>
      <title>Splunk SPL- How do I use regex to create an alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616084#M214093</link>
      <description>&lt;P&gt;Hello Splunker!&lt;/P&gt;
&lt;P&gt;I created below regex from the raw events. And I want to create an alert which show the event in one cloumn only.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| rex field=_raw "Site\|\_\_SYSTEM\__(?&amp;lt;ServiceName&amp;gt;[A-Za-z]+)"
| rex field=_raw "Message\s\=\s(?&amp;lt;Error_Message&amp;gt;.+\:\s[A-Za-z0-9]+)"
| rex field=_raw "failed:\s(?&amp;lt;OrderNumber&amp;gt;[A-Za-z0-9]+)"
| rex field=_raw "httpStatusCode\s\=\s(?&amp;lt;ResponseTime&amp;gt;[0-9]+)"
| rex field=_raw "ResponseTime\s\=\s(?&amp;lt;Reason&amp;gt;.+)"&lt;/LI-CODE&gt;
&lt;P&gt;By using all the fields i want one liner column result like . Please let me know how to concate and use makemv command. And if any other approach then please guide me.&lt;/P&gt;
&lt;TABLE width="133"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="132px" height="25px"&gt;ServiceName&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="132px" height="25px"&gt;Error_Message&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="132px" height="25px"&gt;OrderNumber&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="132px" height="25px"&gt;Reason&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="132px" height="25px"&gt;ResponseTime&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 13:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616084#M214093</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2022-10-06T13:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616087#M214095</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you should explore the transpose command (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose&lt;/A&gt;) that permits to transpose a list of fields from row to column, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex field=_raw "Site\|\_\_SYSTEM\__(?&amp;lt;ServiceName&amp;gt;[A-Za-z]+)"
| rex field=_raw "Message\s\=\s(?&amp;lt;Error_Message&amp;gt;.+\:\s[A-Za-z0-9]+)"
| rex field=_raw "failed:\s(?&amp;lt;OrderNumber&amp;gt;[A-Za-z0-9]+)"
| rex field=_raw "httpStatusCode\s\=\s(?&amp;lt;ResponseTime&amp;gt;[0-9]+)"
| rex field=_raw "ResponseTime\s\=\s(?&amp;lt;Reason&amp;gt;.+)"
| table ServiceName Error_Message OrderNumber ResponseTime Reason
| transpose 5 
| rename "row 1" AS Value 
| fields Value&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 06:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616087#M214095</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-06T06:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616089#M214097</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; I need a result output as below:&lt;BR /&gt;&lt;BR /&gt;ServiceName: Paypal&lt;BR /&gt;Error_Message: Declined payment&lt;BR /&gt;OrderNumber: GGTHLL&lt;BR /&gt;ResponseTime: 500&lt;BR /&gt;Reason: User not registered&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 06:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616089#M214097</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2022-10-06T06:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616097#M214102</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I replicated the output you indicated,&lt;/P&gt;&lt;P&gt;to have both the field name in a column and the value in another column you have to use the same search without the last row:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex field=_raw "Site\|\_\_SYSTEM\__(?&amp;lt;ServiceName&amp;gt;[A-Za-z]+)"
| rex field=_raw "Message\s\=\s(?&amp;lt;Error_Message&amp;gt;.+\:\s[A-Za-z0-9]+)"
| rex field=_raw "failed:\s(?&amp;lt;OrderNumber&amp;gt;[A-Za-z0-9]+)"
| rex field=_raw "httpStatusCode\s\=\s(?&amp;lt;ResponseTime&amp;gt;[0-9]+)"
| rex field=_raw "ResponseTime\s\=\s(?&amp;lt;Reason&amp;gt;.+)"
| table ServiceName Error_Message OrderNumber ResponseTime Reason
| transpose 5 
| rename "row 1" AS Value &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;If instead you want "&amp;lt;fieldname&amp;gt;: &amp;gt;fieldvalue&amp;gt;", you have to use a similar search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex field=_raw "Site\|\_\_SYSTEM\__(?&amp;lt;ServiceName&amp;gt;[A-Za-z]+)"
| rex field=_raw "Message\s\=\s(?&amp;lt;Error_Message&amp;gt;.+\:\s[A-Za-z0-9]+)"
| rex field=_raw "failed:\s(?&amp;lt;OrderNumber&amp;gt;[A-Za-z0-9]+)"
| rex field=_raw "httpStatusCode\s\=\s(?&amp;lt;ResponseTime&amp;gt;[0-9]+)"
| rex field=_raw "ResponseTime\s\=\s(?&amp;lt;Reason&amp;gt;.+)"
| eval 
   ServiceName="ServiceName: ".ServiceName,
   Error_Message="Error_Message: ".Error_Message,
   OrderNumber="OrderNumber: ".OrderNumber,
   ResponseTime="ResponseTime: ".ResponseTime,
   Reason="Reason: ".Reason
| table ServiceName Error_Message OrderNumber ResponseTime Reason
| transpose 5 
| rename "row 1" AS Value 
| table Value&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 06:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616097#M214102</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-06T06:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616111#M214109</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;I tried some workarounds. And I succeed what I want to achieve, that is highlighted in the yellow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1665048097229.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21914i63EDBAD680CA9223/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1665048097229.png" alt="uagraw01_0-1665048097229.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 09:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616111#M214109</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2022-10-06T09:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616112#M214110</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, but this is a different output than the one you shared.&lt;/P&gt;&lt;P&gt;why my solution doesn't work for you, what's the problem?&lt;/P&gt;&lt;P&gt;tell me if you need more help, otherwise, please accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 09:20:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-SPL-How-do-I-use-regex-to-create-an-alert/m-p/616112#M214110</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-06T09:20:38Z</dc:date>
    </item>
  </channel>
</rss>

