<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help extracting multiple fields from a search result in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623831#M216885</link>
    <description>&lt;P&gt;First, if you have any influence at all on the developers, persuade, plea with, beg them to make logs complete. &amp;nbsp;Second, because you are confident that groupid is always included in the login event, I would recommend mending partial JSON to conformant objects, like thus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex mode=sed "s/(\"groupid\": *\"[^\"]+\"),.*/\1}}/"
```| eval valid = if(json_valid(_raw), "yes", "no")```
| spath&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your sample input now becomes&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;context&lt;/TD&gt;&lt;TD&gt;message.agent&lt;/TD&gt;&lt;TD&gt;message.cssurl&lt;/TD&gt;&lt;TD&gt;message.groupid&lt;/TD&gt;&lt;TD&gt;message.loginid&lt;/TD&gt;&lt;TD&gt;message.ownerid&lt;/TD&gt;&lt;TD&gt;message.state&lt;/TD&gt;&lt;TD&gt;message.userid&lt;/TD&gt;&lt;TD&gt;message.username&lt;/TD&gt;&lt;TD&gt;sequence&lt;/TD&gt;&lt;TD&gt;type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Rsomeserver:8877-T1670321752-P18407-T030-C000025-S38&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;["/css/somepage.css","/branding/"]&lt;/TD&gt;&lt;TD&gt;Group0000000945&lt;/TD&gt;&lt;TD&gt;somelogin101&lt;/TD&gt;&lt;TD&gt;system&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;TD&gt;User0000000949&lt;/TD&gt;&lt;TD&gt;John Smith&lt;/TD&gt;&lt;TD&gt;998&lt;/TD&gt;&lt;TD&gt;login&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;This would be much easier to handle.&lt;/P&gt;&lt;P&gt;To achieve your combined search, your want to retrieve all events in both searches, then perform stats on them, like thus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=myindex (("events") OR ("events2")) OR ("\"login\"\,\"context\"") AND ("username")
| rex mode=sed "s/(\"groupid\": *\"[^\"]+\"),.*/\1}}/" ``` you can design another rex to make "events or events2" conformant ```
| spath
| rename message.* AS *
| rex "\"context\"\s*:\"(?&amp;lt;context&amp;gt;.[^\"]+)" | rex "\"type\"\s*:\"(?&amp;lt;type&amp;gt;.[^\"]+)\"" ``` unnecessary if "events or events2" are already mended ```
| stats dc(type) count by username userid groupid context
| where 'dc(type)' &amp;gt; 1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2022 12:41:48 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2022-12-09T12:41:48Z</dc:date>
    <item>
      <title>How to extract multiple fields from a search result?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623664#M216802</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;I am trying to extract the values that trail context, userid, username, groupid&lt;/P&gt;
&lt;P&gt;Sample partial event&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{ "type": "login","context": "Rsomeserver:8877-T1670321752-P18407-T030-C000025-S38","sequence": 998,"message": { "state": "ok","agent": true,"userid": "User0000000949","loginid": "somelogin101","ownerid": "system","username": "John Smith","cssurl": "[\"/css/somepage.css\",\"/branding/\"]","groupid": "Group0000000945","windows": [ {"name":"something","id":"someid","url":"/someurl//&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I started with this approach&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;"context": "(?&amp;lt;SessionID&amp;gt;[^\"]*)".*?"username"+: "(?&amp;lt;Username&amp;gt;[^\"]*)"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And this seems to compile on regex101 but on rex it's throwing an error&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Error in 'SearchParser': Missing a search command before '^'. Error at position '141' of search query 'search index=&amp;lt;removed&amp;gt; ("\"login\"\,\"contex...{snipped} {errorcontext = ?&amp;lt;userid&amp;gt;[^\"]*)"}'.&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My aim is to then use this data to join on the&amp;nbsp; context value with another search, but I'm looking for help on where I'm going wrong with my Rex.&lt;/P&gt;
&lt;P&gt;As the JSON seems to be truncated, I don't think I can treat it as JSON, so any help with a REX extraction would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 19:27:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623664#M216802</guid>
      <dc:creator>hamishcross</dc:creator>
      <dc:date>2022-12-08T19:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: Need help extracting multiple fields from a search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623666#M216804</link>
      <description>&lt;P&gt;Your quotes inside your rex string need to be escaped&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "context\":\s\"(?&amp;lt;SessionID&amp;gt;[^\"]*)\".*?\"username\"+:\s\"(?&amp;lt;Username&amp;gt;[^\"]*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 08 Dec 2022 06:24:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623666#M216804</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-12-08T06:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Need help extracting multiple fields from a search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623667#M216805</link>
      <description>&lt;P&gt;and as a further comment - &lt;EM&gt;&lt;STRONG&gt;join&lt;/STRONG&gt;&lt;/EM&gt; is rarely the right solution to a Splunk join search.&lt;/P&gt;&lt;P&gt;It has limitations and can silently give you the wrong results.&lt;/P&gt;&lt;P&gt;It's best to start looking at solving a join issue with stats, e.g. a typical starting point is&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(search data_set_1) OR (search data_set_2)
| get_session_id_from_data_here
| stats values(*) as * by sessionId&lt;/LI-CODE&gt;&lt;P&gt;and getting the session id will depend on the data set it comes from. This can involve typically&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex data_set_1_field "(?&amp;lt;id_1&amp;gt;session id from here)"
| rex data_set_2_field "(?&amp;lt;id_2&amp;gt;session id from here)"
| eval sessionId=coalesce(id_1, id_2)&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 08 Dec 2022 06:29:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623667#M216805</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-12-08T06:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Need help extracting multiple fields from a search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623827#M216882</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my aim is to execute the below, which should tally up the number of events that a given "context" has executed, and subsequently logged. This context(id) is another name for a session.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=myindex ("events") OR ("events2") | rex "context.{3}\"(?&amp;lt;context&amp;gt;.[a-zA-Z0-9_:-]+)" | stats count by context&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd then like to tie join the above context on the below, so that I can get user details related to above results&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=myindex ("\"login\"\,\"context\"") AND ("username") | rex "context\":\s\"(?&amp;lt;context&amp;gt;[^\"]*)\".*?\"userid\"+:\s\"(?&amp;lt;userid&amp;gt;[^\"]*)\".*?\"username\"+:\s\"(?&amp;lt;username&amp;gt;[^\"]*)\".*?\"groupid\"+:\s\"(?&amp;lt;groupid&amp;gt;[^\"]*)" | table context userid groupid username&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd then like to only show unique rows based on the userid&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And finally, I'd then like to be able to show a count of the unique rows above&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 11:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623827#M216882</guid>
      <dc:creator>hamishcross</dc:creator>
      <dc:date>2022-12-09T11:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Need help extracting multiple fields from a search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623831#M216885</link>
      <description>&lt;P&gt;First, if you have any influence at all on the developers, persuade, plea with, beg them to make logs complete. &amp;nbsp;Second, because you are confident that groupid is always included in the login event, I would recommend mending partial JSON to conformant objects, like thus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex mode=sed "s/(\"groupid\": *\"[^\"]+\"),.*/\1}}/"
```| eval valid = if(json_valid(_raw), "yes", "no")```
| spath&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your sample input now becomes&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;context&lt;/TD&gt;&lt;TD&gt;message.agent&lt;/TD&gt;&lt;TD&gt;message.cssurl&lt;/TD&gt;&lt;TD&gt;message.groupid&lt;/TD&gt;&lt;TD&gt;message.loginid&lt;/TD&gt;&lt;TD&gt;message.ownerid&lt;/TD&gt;&lt;TD&gt;message.state&lt;/TD&gt;&lt;TD&gt;message.userid&lt;/TD&gt;&lt;TD&gt;message.username&lt;/TD&gt;&lt;TD&gt;sequence&lt;/TD&gt;&lt;TD&gt;type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Rsomeserver:8877-T1670321752-P18407-T030-C000025-S38&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;["/css/somepage.css","/branding/"]&lt;/TD&gt;&lt;TD&gt;Group0000000945&lt;/TD&gt;&lt;TD&gt;somelogin101&lt;/TD&gt;&lt;TD&gt;system&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;TD&gt;User0000000949&lt;/TD&gt;&lt;TD&gt;John Smith&lt;/TD&gt;&lt;TD&gt;998&lt;/TD&gt;&lt;TD&gt;login&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;This would be much easier to handle.&lt;/P&gt;&lt;P&gt;To achieve your combined search, your want to retrieve all events in both searches, then perform stats on them, like thus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=myindex (("events") OR ("events2")) OR ("\"login\"\,\"context\"") AND ("username")
| rex mode=sed "s/(\"groupid\": *\"[^\"]+\"),.*/\1}}/" ``` you can design another rex to make "events or events2" conformant ```
| spath
| rename message.* AS *
| rex "\"context\"\s*:\"(?&amp;lt;context&amp;gt;.[^\"]+)" | rex "\"type\"\s*:\"(?&amp;lt;type&amp;gt;.[^\"]+)\"" ``` unnecessary if "events or events2" are already mended ```
| stats dc(type) count by username userid groupid context
| where 'dc(type)' &amp;gt; 1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 12:41:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-multiple-fields-from-a-search-result/m-p/623831#M216885</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-09T12:41:48Z</dc:date>
    </item>
  </channel>
</rss>

