<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help writting a rex query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620406#M215672</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in this case, you have to use two rex commands:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "NOTE\=\"\w+\d:(?&amp;lt;field1&amp;gt;\d+),(?&amp;lt;field2&amp;gt;\d+)[^;]+;\w+\d:(?&amp;lt;field3&amp;gt;\d+),(?&amp;lt;field4&amp;gt;\d+)"
| rex "NOTE\=\"\w+\d:(?&amp;lt;field1&amp;gt;\d+),(?&amp;lt;field2&amp;gt;\d+)[^;]+;\w+\d:(?&amp;lt;field3&amp;gt;\d+),(?&amp;lt;field4&amp;gt;\d+).*?DEL:\s+(?&amp;lt;field5&amp;gt;\d+),(?&amp;lt;field6&amp;gt;[^;]*;)DEL:\s+(?&amp;lt;field7&amp;gt;\d+),(?&amp;lt;field8&amp;gt;[^;]*);"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2022 12:07:13 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-11-10T12:07:13Z</dc:date>
    <item>
      <title>Need help writting a rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620385#M215660</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;For starter, I'm an amateur in regex query, so I use Field Extraction, but it's very clunky and cannot extract all the fields I want and also sometime have wrong extraction.&lt;/P&gt;&lt;P&gt;The event that I want to extract is&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;2022&lt;/SPAN&gt;-11-09&lt;/SPAN&gt; &lt;SPAN class=""&gt;17:36:05&lt;/SPAN&gt; &lt;SPAN class=""&gt;BANK_CITAD_ID=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;79303001&lt;/SPAN&gt;", &lt;SPAN class=""&gt;SOTIEN_CONLAI=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;150000000&lt;/SPAN&gt;", &lt;SPAN class=""&gt;UPDATED_DATE=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2022-11-09&lt;/SPAN&gt; &lt;SPAN class=""&gt;17:36:05.0&lt;/SPAN&gt;", &lt;SPAN class=""&gt;FILE_NAME=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;GTCG_dinhky_20221109.xlsx&lt;/SPAN&gt;", &lt;SPAN class=""&gt;STATUS=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;DATA_ERROR&lt;/SPAN&gt;", &lt;SPAN class=""&gt;ERROR_MSG=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;NOT_ALLOW_LIMIT&lt;/SPAN&gt;", &lt;SPAN class=""&gt;SOTIENTANG=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;0&lt;/SPAN&gt;", &lt;SPAN class=""&gt;SOTIENGIAM=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;0&lt;/SPAN&gt;", &lt;SPAN class=""&gt;LOAI_FILE=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;DK&lt;/SPAN&gt;", &lt;SPAN class=""&gt;STT=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2&lt;/SPAN&gt;", &lt;SPAN class=""&gt;BANK_CODE=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;STB&lt;/SPAN&gt;", &lt;SPAN class=""&gt;ID=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;6829&lt;/SPAN&gt;", &lt;SPAN class=""&gt;NOTE=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;DC1&lt;STRONG&gt;:&lt;U&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;2286754104070&lt;/EM&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;,&lt;U&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/U&gt;,&lt;SPAN class=""&gt;10/11/2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;00:00:00&lt;/SPAN&gt;;&lt;SPAN class=""&gt;DC2:&lt;FONT color="#FF0000"&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;10000000000&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/SPAN&gt;,&lt;U&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;1501000000&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/U&gt;,&lt;SPAN class=""&gt;10/11/2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;00:00:00&lt;/SPAN&gt;,&lt;SPAN class=""&gt;1000001&lt;/SPAN&gt;;&lt;SPAN class=""&gt;DEL:&lt;/SPAN&gt; &lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class=""&gt;1501000001&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;,&lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class=""&gt;10/11/2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;00:00:00&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;;&lt;SPAN class=""&gt;DEL:&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;&lt;FONT color="#FF0000"&gt; &lt;SPAN class=""&gt;1501000001&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;,&lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class=""&gt;10/11/2022&lt;/SPAN&gt; &lt;SPAN class=""&gt;00:00:00&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;;"&lt;/P&gt;&lt;P&gt;There are a total of 8 fields that I want to extract, the field name can be field1, field2..., at least that I can handle.&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 09:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620385#M215660</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2022-11-10T09:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writting a rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620388#M215662</link>
      <description>&lt;P&gt;hI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you said 8 fields meaning that each red highlighted string is divided in two fields by comma, is it correct?&lt;/P&gt;&lt;P&gt;in this case, you could try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "NOTE\=\"\w+\d:(?&amp;lt;field1&amp;gt;\d+),(?&amp;lt;field2&amp;gt;\d+)[^;]+;\w+\d:(?&amp;lt;field3&amp;gt;\d+),(?&amp;lt;field4&amp;gt;\d+).*?DEL:\s+(?&amp;lt;field5&amp;gt;\d+),(?&amp;lt;field6&amp;gt;[^;]*;)DEL:\s+(?&amp;lt;field7&amp;gt;\d+),(?&amp;lt;field8&amp;gt;[^;]*);"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/GTz8Dd/1" target="_blank"&gt;https://regex101.com/r/GTz8Dd/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 10:01:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620388#M215662</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-10T10:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writting a rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620393#M215667</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your rex only work if the event content all the fields. I forgot to mention that field5, field6, field7, field8 sometime don't apper, field1-&amp;gt;field4 always there. The event could be (without DEL)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2022-11-10 13:46:12 BANK_CITAD_ID="79303001", SOTIEN_CONLAI="150000000", UPDATED_DATE="2022-11-10 13:46:12.0", FILE_NAME="GTCG_dinhky_20221110.xlsx", STATUS="DATA_ERROR", ERROR_MSG="NOT_ALLOW_LIMIT", SOTIENTANG="0", SOTIENGIAM="0", LOAI_FILE="DK", STT="2", BANK_CODE="STB", ID="6838", NOTE="DC1:1,1,11/11/2022 00:00:00;DC2:1501000000,1501000000,11/11/2022 00:00:00,999999;"&lt;/LI-CODE&gt;&lt;P&gt;Or it only have 1 DEL, like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2022-11-09 17:36:05 BANK_CITAD_ID="01202001", SOTIEN_CONLAI="67499999", UPDATED_DATE="2022-11-09 17:36:05.0", FILE_NAME="GTCG_dinhky_20221109_2.xlsx", STATUS="DATA_ERROR", ERROR_MSG="NOT_ALLOW_LIMIT", SOTIENTANG="0", SOTIENGIAM="0", LOAI_FILE="DK", STT="1", BANK_CODE="BIDV", ID="6831", NOTE="DC1:3350000000000,1,10/11/2022 00:00:00;DC2:250000000000,675000000,10/11/2022 00:00:00,11;DEL: 675000001,10/11/2022 00:00:00;"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 10:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620393#M215667</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2022-11-10T10:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writting a rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620406#M215672</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in this case, you have to use two rex commands:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "NOTE\=\"\w+\d:(?&amp;lt;field1&amp;gt;\d+),(?&amp;lt;field2&amp;gt;\d+)[^;]+;\w+\d:(?&amp;lt;field3&amp;gt;\d+),(?&amp;lt;field4&amp;gt;\d+)"
| rex "NOTE\=\"\w+\d:(?&amp;lt;field1&amp;gt;\d+),(?&amp;lt;field2&amp;gt;\d+)[^;]+;\w+\d:(?&amp;lt;field3&amp;gt;\d+),(?&amp;lt;field4&amp;gt;\d+).*?DEL:\s+(?&amp;lt;field5&amp;gt;\d+),(?&amp;lt;field6&amp;gt;[^;]*;)DEL:\s+(?&amp;lt;field7&amp;gt;\d+),(?&amp;lt;field8&amp;gt;[^;]*);"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 12:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620406#M215672</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-10T12:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writting a rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620470#M215701</link>
      <description>&lt;P&gt;So what if I try to rex the date from DC1 and DC2 as well, I try to modify your rex to&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "NOTE\=\"\w+\d:(?&amp;lt;field1&amp;gt;\d+),(?&amp;lt;field2&amp;gt;\d+),(?&amp;lt;field3&amp;gt;[^;]*);[^;]+;\w+\d:(?&amp;lt;field4&amp;gt;\d+),(?&amp;lt;field5&amp;gt;\d+)(?&amp;lt;field6&amp;gt;[^;]*);" 
| rex "NOTE\=\"\w+\d:(?&amp;lt;field1&amp;gt;\d+),(?&amp;lt;field2&amp;gt;\d+),(?&amp;lt;field3&amp;gt;[^;]*);[^;]+;\w+\d:(?&amp;lt;field4&amp;gt;\d+),(?&amp;lt;field5&amp;gt;\d+)(?&amp;lt;field6&amp;gt;[^;]*);.*?DEL:\s+(?&amp;lt;field7&amp;gt;\d+),(?&amp;lt;field8&amp;gt;[^;]*;)DEL:\s+(?&amp;lt;field9&amp;gt;\d+),(?&amp;lt;field10&amp;gt;[^;]*);"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but it broke the rex completely.&lt;/P&gt;&lt;P&gt;Could you tell me where do I write it wrong and how could I fix this?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 16:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/620470#M215701</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2022-11-10T16:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writting a rex query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/623200#M216647</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the approach should be of putting the data source in regex101.com and test or adapt the regex there.&lt;/P&gt;&lt;P&gt;Then you can bring it and test again in Splunk search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 08:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-writting-a-rex-query/m-p/623200#M216647</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-05T08:47:22Z</dc:date>
    </item>
  </channel>
</rss>

