<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need rex to extract field. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/626972#M217891</link>
    <description>&lt;P&gt;The rex command works for me.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "identification=(?&amp;lt;identification&amp;gt;\w+)"&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 12 Jan 2023 20:19:27 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-01-12T20:19:27Z</dc:date>
    <item>
      <title>How to create rex to extract field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/626970#M217889</link>
      <description>&lt;P&gt;From here i need to extarct the identification=MLAS, MLA, LAS and VAM&lt;BR /&gt;My sample logs:&lt;BR /&gt;[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid="7689-jhgg-8765r-kkjggt"; app=" "; QueryLetter="yard=MS&amp;amp;identification=MLAS&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES&lt;BR /&gt;&lt;BR /&gt;[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid="7689-jhgg-8765r-kkjggt"; app=" "; QueryLetter="yard=MS&amp;amp;identification=MLA&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES&lt;/P&gt;
&lt;P&gt;[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid="7689-jhgg-8765r-kkjggt"; app=" "; QueryLetter="yard=MS&amp;amp;identification=LAS&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES&lt;BR /&gt;&lt;BR /&gt;[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid="7689-jhgg-8765r-kkjggt"; app=" "; QueryLetter="yard=MS&amp;amp;identification=VAM&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES&lt;BR /&gt;&lt;BR /&gt;in my selected fileds or intresting fileds&amp;nbsp; indeentification fileds&amp;nbsp; should appear has below:&lt;BR /&gt;MLAS&lt;BR /&gt;MLA&lt;BR /&gt;LAS&amp;nbsp;&lt;BR /&gt;VAM&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 20:40:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/626970#M217889</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-12T20:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Need rex to extract field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/626972#M217891</link>
      <description>&lt;P&gt;The rex command works for me.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "identification=(?&amp;lt;identification&amp;gt;\w+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 12 Jan 2023 20:19:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/626972#M217891</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-12T20:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to create rex to extract field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/627036#M217921</link>
      <description>&lt;P&gt;Are posted logs raw events? &amp;nbsp;Is there some settings in your sourcetype (props.conf) that prevents automatic extraction of the fields you wanted? &amp;nbsp;Because the field names and values are connected by equal sign, Splunk should have already extracted them.&lt;/P&gt;&lt;P&gt;Here is an emulation of your samples:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval data = split("[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid=\"7689-jhgg-8765r-kkjggt\"; app=\" \"; QueryLetter=\"yard=MS&amp;amp;identification=MLAS&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES
[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid=\"7689-jhgg-8765r-kkjggt\"; app=\" \"; QueryLetter=\"yard=MS&amp;amp;identification=MLA&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES
[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid=\"7689-jhgg-8765r-kkjggt\"; app=\" \"; QueryLetter=\"yard=MS&amp;amp;identification=LAS&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES
[12/12/21] 12:10:112 GMT] I6789HIOO applicattion authenticationid=100| |35467577889999| |67775-ghhgfrt-6788h-7667788; clientid=\"7689-jhgg-8765r-kkjggt\"; app=\" \"; QueryLetter=\"yard=MS&amp;amp;identification=VAM&amp;amp;timeRange=EVERYDAY&amp;amp;timePeriod=MINUTES", "
")
| mvexpand data
| rename data AS _raw
| extract&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;These are the fields extracted:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;QueryLetter&lt;/TD&gt;&lt;TD&gt;app&lt;/TD&gt;&lt;TD&gt;authenticationid&lt;/TD&gt;&lt;TD&gt;clientid&lt;/TD&gt;&lt;TD&gt;identification&lt;/TD&gt;&lt;TD&gt;timePeriod&lt;/TD&gt;&lt;TD&gt;timeRange&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;"yard=MS&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;100| |35467577889999| |67775-ghhgfrt-6788h-7667788&lt;/TD&gt;&lt;TD&gt;7689-jhgg-8765r-kkjggt&lt;/TD&gt;&lt;TD&gt;MLAS&lt;/TD&gt;&lt;TD&gt;MINUTES&lt;/TD&gt;&lt;TD&gt;EVERYDAY&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;"yard=MS&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;100| |35467577889999| |67775-ghhgfrt-6788h-7667788&lt;/TD&gt;&lt;TD&gt;7689-jhgg-8765r-kkjggt&lt;/TD&gt;&lt;TD&gt;MLA&lt;/TD&gt;&lt;TD&gt;MINUTES&lt;/TD&gt;&lt;TD&gt;EVERYDAY&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;"yard=MS&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;100| |35467577889999| |67775-ghhgfrt-6788h-7667788&lt;/TD&gt;&lt;TD&gt;7689-jhgg-8765r-kkjggt&lt;/TD&gt;&lt;TD&gt;LAS&lt;/TD&gt;&lt;TD&gt;MINUTES&lt;/TD&gt;&lt;TD&gt;EVERYDAY&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;"yard=MS&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;100| |35467577889999| |67775-ghhgfrt-6788h-7667788&lt;/TD&gt;&lt;TD&gt;7689-jhgg-8765r-kkjggt&lt;/TD&gt;&lt;TD&gt;VAM&lt;/TD&gt;&lt;TD&gt;MINUTES&lt;/TD&gt;&lt;TD&gt;EVERYDAY&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 13 Jan 2023 08:31:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/627036#M217921</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-01-13T08:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need rex to extract field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/627524#M218054</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;it worked, thank you&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 21:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-rex-to-extract-field/m-p/627524#M218054</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-18T21:14:22Z</dc:date>
    </item>
  </channel>
</rss>

