<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract for field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-extract-using-rex-command/m-p/620366#M215666</link>
    <description>&lt;P&gt;Assuming the field is as written and is in the _raw field&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "user id\":\"(?&amp;lt;user_id&amp;gt;[^\"]*)\",\s+\"Expense Date\":\"(?&amp;lt;expense_date&amp;gt;[^\"]*)"&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 10 Nov 2022 05:36:54 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2022-11-10T05:36:54Z</dc:date>
    <item>
      <title>How to use extract using rex command?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-extract-using-rex-command/m-p/620364#M215665</link>
      <description>&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Context&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"{"user&lt;/SPAN&gt;&amp;nbsp;id&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;jane.doe.sen&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;SPAN class=""&gt;Expense&lt;/SPAN&gt; &lt;SPAN class=""&gt;Date&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;"11&lt;SPAN class=""&gt;/10/2022&lt;/SPAN&gt;",&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How to use extract this rex command?&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;to come up result like&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE border="0" width="128" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="64" height="20"&gt;user&amp;nbsp;id&lt;/TD&gt;
&lt;TD width="64"&gt;Expense Date&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="20"&gt;jane.doe.sen&lt;/TD&gt;
&lt;TD&gt;9/6/2022&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN&gt;please help&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:35:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-extract-using-rex-command/m-p/620364#M215665</guid>
      <dc:creator>wvsgo215</dc:creator>
      <dc:date>2022-11-10T15:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Extract for field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-extract-using-rex-command/m-p/620366#M215666</link>
      <description>&lt;P&gt;Assuming the field is as written and is in the _raw field&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "user id\":\"(?&amp;lt;user_id&amp;gt;[^\"]*)\",\s+\"Expense Date\":\"(?&amp;lt;expense_date&amp;gt;[^\"]*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 10 Nov 2022 05:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-extract-using-rex-command/m-p/620366#M215666</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-11-10T05:36:54Z</dc:date>
    </item>
  </channel>
</rss>

