<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extracting Field using Regexes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extracting-Field-using-Regexes/m-p/84517#M21543</link>
    <description>&lt;P&gt;I have extracted the latitude using this (?i).Double"&amp;gt;(?P&lt;FIELDNAME&gt;[^&amp;lt;]+ , but i could not extract the longitude as both shares the double. Anyway that I can extract longitude ?&lt;/FIELDNAME&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;updated&amp;gt;2013-07-04T06:03:39Z&amp;lt;/updated&amp;gt;
&amp;lt;author&amp;gt;
  &amp;lt;name /&amp;gt;
&amp;lt;/author&amp;gt;
&amp;lt;link rel="edit" title="Nowcast" href="NowcastSet(1310755)" /&amp;gt;
&amp;lt;category term="NEAModel.Nowcast" scheme="http://schemas.microsoft.com/ado/2007/08/dataservices/scheme" /&amp;gt;
&amp;lt;content type="application/xml"&amp;gt;
  &amp;lt;m:properties&amp;gt;
    &amp;lt;d:NowcastID m:type="Edm.Int32"&amp;gt;1310755&amp;lt;/d:NowcastID&amp;gt;
    &amp;lt;d:Area&amp;gt;Yishun&amp;lt;/d:Area&amp;gt;
    &amp;lt;d:Condition&amp;gt;Rain&amp;lt;/d:Condition&amp;gt;
    &amp;lt;d:Latitude m:type="Edm.Double"&amp;gt;1.42738834&amp;lt;/d:Latitude&amp;gt;
    &amp;lt;d:Longitude m:type="Edm.Double"&amp;gt;103.8290405&amp;lt;/d:Longitude&amp;gt;
    &amp;lt;d:Summary&amp;gt;Rain&amp;lt;/d:Summary&amp;gt;
    &amp;lt;d:Distance m:type="Edm.Double"&amp;gt;0&amp;lt;/d:Distance&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 04 Jul 2013 06:12:13 GMT</pubDate>
    <dc:creator>sbnoobbb</dc:creator>
    <dc:date>2013-07-04T06:12:13Z</dc:date>
    <item>
      <title>Extracting Field using Regexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-Field-using-Regexes/m-p/84517#M21543</link>
      <description>&lt;P&gt;I have extracted the latitude using this (?i).Double"&amp;gt;(?P&lt;FIELDNAME&gt;[^&amp;lt;]+ , but i could not extract the longitude as both shares the double. Anyway that I can extract longitude ?&lt;/FIELDNAME&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;updated&amp;gt;2013-07-04T06:03:39Z&amp;lt;/updated&amp;gt;
&amp;lt;author&amp;gt;
  &amp;lt;name /&amp;gt;
&amp;lt;/author&amp;gt;
&amp;lt;link rel="edit" title="Nowcast" href="NowcastSet(1310755)" /&amp;gt;
&amp;lt;category term="NEAModel.Nowcast" scheme="http://schemas.microsoft.com/ado/2007/08/dataservices/scheme" /&amp;gt;
&amp;lt;content type="application/xml"&amp;gt;
  &amp;lt;m:properties&amp;gt;
    &amp;lt;d:NowcastID m:type="Edm.Int32"&amp;gt;1310755&amp;lt;/d:NowcastID&amp;gt;
    &amp;lt;d:Area&amp;gt;Yishun&amp;lt;/d:Area&amp;gt;
    &amp;lt;d:Condition&amp;gt;Rain&amp;lt;/d:Condition&amp;gt;
    &amp;lt;d:Latitude m:type="Edm.Double"&amp;gt;1.42738834&amp;lt;/d:Latitude&amp;gt;
    &amp;lt;d:Longitude m:type="Edm.Double"&amp;gt;103.8290405&amp;lt;/d:Longitude&amp;gt;
    &amp;lt;d:Summary&amp;gt;Rain&amp;lt;/d:Summary&amp;gt;
    &amp;lt;d:Distance m:type="Edm.Double"&amp;gt;0&amp;lt;/d:Distance&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Jul 2013 06:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-Field-using-Regexes/m-p/84517#M21543</guid>
      <dc:creator>sbnoobbb</dc:creator>
      <dc:date>2013-07-04T06:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting Field using Regexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-Field-using-Regexes/m-p/84518#M21544</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;You can use those Regexes:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt; d:Latitude m:type="Edm.Double"&amp;gt;(?&amp;lt;Latitude&amp;gt;\d+\.\d+)&amp;lt; /d:Latitude&amp;gt;
&amp;lt; d:Longitude m:type="Edm.Double"&amp;gt;(?&amp;lt;Latitude&amp;gt;\d+\.\d+)&amp;lt; /d:Longitude&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;*Remove the blanks after the angle bracket&lt;BR /&gt;
Regards&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2013 06:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-Field-using-Regexes/m-p/84518#M21544</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2013-07-04T06:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting Field using Regexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-Field-using-Regexes/m-p/84519#M21545</link>
      <description>&lt;P&gt;I have used this and it works &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt; Thanks anyway !&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;(?&lt;CURRENT_LONGITUDE&gt;[^&amp;lt;]+)&amp;lt;/d:Longitude&lt;/CURRENT_LONGITUDE&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 04 Jul 2013 07:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-Field-using-Regexes/m-p/84519#M21545</guid>
      <dc:creator>sbnoobbb</dc:creator>
      <dc:date>2013-07-04T07:17:02Z</dc:date>
    </item>
  </channel>
</rss>

