<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to search results and present as a table of selected key vaule? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619342#M215253</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The log has empty space before and after equal with semicolon separation. I’m unable to get the table request status like index="gd" RequestStatus | table RequestStatus, _time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Would you please advise if anyone have suggestions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Log sample&lt;/P&gt;
&lt;P&gt;{"timestamp":"2022-11-02 17:01:21,421+0000","level":"INFO","location":"request_process:171","message":"request_id = 5ac3565f-d964-31cd-90b1-e8b7b208e7df; RequestStatus = Completed; RequestID = 5ac3565f-d9a64-31cd-9021-e8b7b208e7df--70ivkG0Td8OBpvWk; S3SourceKey = 1049x7555.xml ; "function_request_id":"b61aa34-f22b-53bc-957e-142456b9b7a5","xray_id":"1-6482a25d-78459fbe07213ee14x4386bd"}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RequestStatus = Received&lt;/P&gt;
&lt;P&gt;RequestStatus = Completed&lt;/P&gt;
&lt;P&gt;RequestStatus = Error&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 20:14:21 GMT</pubDate>
    <dc:creator>padrsri</dc:creator>
    <dc:date>2022-11-02T20:14:21Z</dc:date>
    <item>
      <title>How to search results and present as a table of selected key vaule?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619342#M215253</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The log has empty space before and after equal with semicolon separation. I’m unable to get the table request status like index="gd" RequestStatus | table RequestStatus, _time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Would you please advise if anyone have suggestions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Log sample&lt;/P&gt;
&lt;P&gt;{"timestamp":"2022-11-02 17:01:21,421+0000","level":"INFO","location":"request_process:171","message":"request_id = 5ac3565f-d964-31cd-90b1-e8b7b208e7df; RequestStatus = Completed; RequestID = 5ac3565f-d9a64-31cd-9021-e8b7b208e7df--70ivkG0Td8OBpvWk; S3SourceKey = 1049x7555.xml ; "function_request_id":"b61aa34-f22b-53bc-957e-142456b9b7a5","xray_id":"1-6482a25d-78459fbe07213ee14x4386bd"}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RequestStatus = Received&lt;/P&gt;
&lt;P&gt;RequestStatus = Completed&lt;/P&gt;
&lt;P&gt;RequestStatus = Error&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 20:14:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619342#M215253</guid>
      <dc:creator>padrsri</dc:creator>
      <dc:date>2022-11-02T20:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619346#M215255</link>
      <description>&lt;P&gt;Here's the most straightforward way (IMO). It uses the &lt;FONT face="courier new,courier"&gt;rex&lt;/FONT&gt; command to extract the RequestStatus field.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="gd" RequestStatus
| rex "RequestStatus = (?&amp;lt;RequestStatus&amp;gt;\S+)"
| table RequestStatus, _time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 18:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619346#M215255</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-02T18:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619357#M215259</link>
      <description>&lt;P&gt;Thank you for quick response and the solutions helped us.&lt;/P&gt;&lt;P&gt;Somehow, I’m not able to get Received request Id in search (sample log). Also is there any way to disable as report like below?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;RequestStatus status&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;message: css_request_id = abceesxs-e8cf-383a-81d6-78185430c323; RequestStatus = Received; EnvName = tst111; RequestId = abceesxs-e8cf-383a-81d6-78185430c323--HO1FQtsdshNVf80E; bucket = testbucket; key = DATA.xml; attempts = 1;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Completed status&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;message: css_request_id = abceesxs-e8cf-383a-81d6-78185430c323; RequestStatus = Completed; RequestID = abceesxs-e8cf-383a-81d6-78185430c323--HO1FQtsdshNVf80E; responseStatusCode = True; platformBuckets = ['css-lpue1-platform-data-application', 'css-lpue2-platform-data-application']; key = DATA.xml; bucket = testbucket; sourceKey = 10497687_DATA.xml ;&amp;nbsp;&lt;BR /&gt;service: gwy-Inbound&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Search index&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;index="gd" RequestStatus RequestID | rex "RequestStatus = (?&amp;lt;RequestStatus&amp;gt;\S+)" | rex "RequestID = ?[\S+](?&amp;lt;RequestID&amp;gt;[\S+]*)" | table RequestID, RequestStatus, _time&lt;/P&gt;&lt;P&gt;Report like&amp;nbsp;&lt;/P&gt;&lt;P&gt;RequestID, RequestStatus , _time&lt;BR /&gt;-------------------------------------------------&lt;BR /&gt;11111111 Received,Completed 2022-11-02 17:01:21&lt;BR /&gt;11111112 Received,Completed 2022-11-02 17:01:21&lt;BR /&gt;11111113 Received,Completed 2022-11-02 17:01:21&lt;BR /&gt;11111114 Received,Error 2022-11-02 17:01:21&lt;BR /&gt;11111115 Received,Completed 2022-11-02 17:01:21&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 19:36:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619357#M215259</guid>
      <dc:creator>padrsri</dc:creator>
      <dc:date>2022-11-02T19:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619358#M215260</link>
      <description>&lt;P&gt;You have the right idea, but the RequestID regex needs improvement.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="gd" RequestStatus RequestID 
| rex "RequestStatus = (?&amp;lt;RequestStatus&amp;gt;\S+)" 
| rex "RequestID = (?&amp;lt;RequestID&amp;gt;\S+)" 
| table RequestID, RequestStatus, _time&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 02 Nov 2022 19:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619358#M215260</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-02T19:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619360#M215261</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&amp;nbsp;Richgalloway,&lt;/P&gt;&lt;P&gt;Thank you for quick response.&amp;nbsp; somehow, I'm not getting request ID for "RequestStatus = Received; EnvName = tst111; RequestId = abceesxs-e8cf-383a-81d6-78185430c323--HO1FQtsdshNVf80E;" ..&amp;nbsp; do i need regex to excluded "EnvName = tst111;"?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 20:35:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619360#M215261</guid>
      <dc:creator>padrsri</dc:creator>
      <dc:date>2022-11-02T20:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619378#M215269</link>
      <description>&lt;P&gt;The RequestID tag is not consistent - sometimes it uses 'D' and sometimes 'd'.&amp;nbsp; This query should handle that.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="gd" RequestStatus RequestID 
| rex "RequestStatus = (?&amp;lt;RequestStatus&amp;gt;\S+)" 
| rex "RequestI[Dd] = (?&amp;lt;RequestID&amp;gt;\S+)" 
| table RequestID, RequestStatus, _time&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 02 Nov 2022 23:50:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619378#M215269</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-02T23:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619450#M215289</link>
      <description>&lt;P&gt;Thank you for all your help, it's is working as expected&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 13:19:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619450#M215289</guid>
      <dc:creator>padrsri</dc:creator>
      <dc:date>2022-11-03T13:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619452#M215291</link>
      <description>&lt;P&gt;Thank you for all your help. The search is working fine now.&amp;nbsp; Is it possible to display as report like ? Can you please advise&lt;/P&gt;&lt;P&gt;Search index&amp;nbsp;index="mw_ib_prf507" RequestStatus RequestID&lt;BR /&gt;| rex "RequestStatus = (?&amp;lt;RequestStatus&amp;gt;\S+)"&lt;BR /&gt;| rex "RequestI[Dd] = (?&amp;lt;RequestID&amp;gt;\S+)"&lt;BR /&gt;| table RequestID, RequestStatus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Request Id &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RequestStatus&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RequestStatusCount&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;11111111 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received,Completed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;11111112 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received,Completed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;11111113 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received,Completed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;11111114 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received,Error &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;11111115 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received,Completed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;11111115 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 13:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619452#M215291</guid>
      <dc:creator>padrsri</dc:creator>
      <dc:date>2022-11-03T13:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to search results and present as a table of selected key vaule</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619681#M215372</link>
      <description>&lt;P&gt;I'm not sure how to do that.&amp;nbsp; Sorry.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 15:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-results-and-present-as-a-table-of-selected-key/m-p/619681#M215372</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-04T15:59:32Z</dc:date>
    </item>
  </channel>
</rss>

