<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636563#M221073</link>
    <description>&lt;P&gt;If you cannot reduce dataset as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;suggested, mvexpand is not suitable. &amp;nbsp;Alternatives see my answer above.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2023 17:40:03 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2023-03-29T17:40:03Z</dc:date>
    <item>
      <title>Help with field extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633182#M219951</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;we have events like below and in these need to extracts below id"s example&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;d1c35370&lt;/SPAN&gt;-1522-498c-8a79-ab07909a1c4a&lt;/SPAN&gt;&amp;nbsp; as new fields with in the status is running&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have muliple ID"S like this in the event&amp;nbsp;&lt;/P&gt;
&lt;P&gt;status is like running and&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running in field&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;it will also show if value other than running&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;-03-03T08:19:31&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;693&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;prod&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;2f78061f-5f51-4636-8da1-3c9644b9e7a1&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;34d3d64e-01c8-428e-a7b1-8b414dbd5478&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;agent-AgentDataSourceStateManagerActor&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;All&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;health&lt;/SPAN&gt; &lt;SPAN class=""&gt;status&lt;/SPAN&gt; &lt;SPAN class=""&gt;has&lt;/SPAN&gt; &lt;SPAN class=""&gt;been&lt;/SPAN&gt; &lt;SPAN class=""&gt;updated-&lt;/SPAN&gt; &lt;SPAN class=""&gt;stateMap:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Map&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;d55c495c-52da-4e57-bc83-2ee02e92d978&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8194d562-beb4-4a44-a7f3-ec92ed549b3c&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;e6f1b795-bf44-4640-880f-8b32f69586b7&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;4925c2fc-7f47-46e5-9a78-63e596bb469a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;d1c35370-1522-498c-8a79-ab07909a1c4a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8e7f28fa-26e9-445a-a5b3-50e5746ca8ca&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;db52b5b0-31b2-43dc-8887-9f2859762a62&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;)], &lt;/SPAN&gt;&lt;SPAN class=""&gt;statusMap:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Map&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;d55c495c-52da-4e57-bc83-2ee02e92d978&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8194d562-beb4-4a44-a7f3-ec92ed549b3c&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;e6f1b795-bf44-4640-880f-8b32f69586b7&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;4925c2fc-7f47-46e5-9a78-63e596bb469a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;d1c35370-1522-498c-8a79-ab07909a1c4a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8e7f28fa-26e9-445a-a5b3-50e5746ca8ca&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;db52b5b0-31b2-43dc-8887-9f2859762a62&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;)]&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 14:22:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633182#M219951</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-03-06T14:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633188#M219956</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "((\[Map\()|(,\s+))(?&amp;lt;id&amp;gt;\w*-\w*-\w*-\w*-\w*)\s+-\&amp;gt;\s+(?&amp;lt;status&amp;gt;[^,]*)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/YLxfkD/1" target="_blank"&gt;https://regex101.com/r/YLxfkD/1&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 14:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633188#M219956</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-03T14:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633198#M219959</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex max_match=0 "((\[Map\()|(,\s+))(?&amp;lt;id&amp;gt;\w*-\w*-\w*-\w*-\w*)\s+-\&amp;gt;\s+(?&amp;lt;status&amp;gt;[^,\)]*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 03 Mar 2023 15:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633198#M219959</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-03T15:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633734#M220110</link>
      <description>&lt;P&gt;Hai All,&lt;/P&gt;&lt;P&gt;thanks but when using regex and search with&amp;nbsp;&lt;/P&gt;&lt;P&gt;sourcetype = netapp:cloudsecure:agentlog | rex max_match=0 "((\[Map\()|(,\s+))(?&amp;lt;id&amp;gt;\w*-\w*-\w*-\w*-\w*)\s+-\&amp;gt;\s+(?&amp;lt;status&amp;gt;[^,\)]*)" | search id="08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad" status="Collector is running."&lt;/P&gt;&lt;P&gt;it was showing events data with other ID"s as well as below.&lt;/P&gt;&lt;P&gt;how can i divide this data&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2023-03-08T08:17:33&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;625&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;prod&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;2f78061f-5f51-4636-8da1-3c9644b9e7a1&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;34d3d64e-01c8-428e-a7b1-8b414dbd5478&lt;/SPAN&gt;&lt;SPAN&gt;] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;agent-AgentDataSourceStateManagerActor&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;All&lt;/SPAN&gt; &lt;SPAN class=""&gt;collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;health&lt;/SPAN&gt; &lt;SPAN class=""&gt;status&lt;/SPAN&gt; &lt;SPAN class=""&gt;has&lt;/SPAN&gt; &lt;SPAN class=""&gt;been&lt;/SPAN&gt; &lt;SPAN class=""&gt;updated-&lt;/SPAN&gt; &lt;SPAN class=""&gt;stateMap:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Map&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;d55c495c-52da-4e57-bc83-2ee02e92d978&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8194d562-beb4-4a44-a7f3-ec92ed549b3c&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;e6f1b795-bf44-4640-880f-8b32f69586b7&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;4925c2fc-7f47-46e5-9a78-63e596bb469a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;d1c35370-1522-498c-8a79-ab07909a1c4a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8e7f28fa-26e9-445a-a5b3-50e5746ca8ca&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;db52b5b0-31b2-43dc-8887-9f2859762a62&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;)], &lt;/SPAN&gt;&lt;SPAN class=""&gt;statusMap:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Map&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;d55c495c-52da-4e57-bc83-2ee02e92d978&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8194d562-beb4-4a44-a7f3-ec92ed549b3c&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;e6f1b795-bf44-4640-880f-8b32f69586b7&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;4925c2fc-7f47-46e5-9a78-63e596bb469a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;d1c35370-1522-498c-8a79-ab07909a1c4a&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;8e7f28fa-26e9-445a-a5b3-50e5746ca8ca&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;db52b5b0-31b2-43dc-8887-9f2859762a62&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Collector&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;running.&lt;/SPAN&gt;&lt;SPAN&gt;)]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 14:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633734#M220110</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-03-08T14:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633744#M220112</link>
      <description>&lt;P&gt;This id exists in this event which is why it is showing. Perhaps if you show what it is you are expecting to be able to show, we might be able to point you in the right direction.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 15:03:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/633744#M220112</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-08T15:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/634037#M220213</link>
      <description>&lt;P&gt;hai i need to deivide the data based on the ID"S so if filter with id filed it will shows the data about only those ID"S not other ID"S data&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 10:38:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/634037#M220213</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-03-10T10:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/634041#M220214</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex max_match=0 "((\[Map\()|(,\s+))(?&amp;lt;id_status&amp;gt;\w*-\w*-\w*-\w*-\w*\s+-\&amp;gt;\s+[^,\)]*)"
| mvexpand id_status
| rex field=id_status "(?&amp;lt;id&amp;gt;\w*-\w*-\w*-\w*-\w*)\s+-\&amp;gt;\s+(?&amp;lt;status&amp;gt;[^,\)]*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 10 Mar 2023 11:08:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/634041#M220214</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-10T11:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636266#M220969</link>
      <description>&lt;P&gt;its working&amp;nbsp;&lt;/P&gt;&lt;P&gt;but i am getting error as&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;command.mvexpand: output will be truncated at 67200 results due to excessive memory usage. Memory threshold of 500MB as configured in limits.conf / [mvexpand] / max_mem_usage_mb has been reached.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;how can i overcome this&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 08:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636266#M220969</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-03-28T08:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636279#M220974</link>
      <description>&lt;P&gt;Reduce your data set - you could try splitting the search into chunks which are appended, but it depends on your data and what you are trying to do. You could also try storing the chunks in a summary index (for example) to offload some of the processing.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 10:08:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636279#M220974</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-28T10:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636303#M220984</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;said, how you handle memory limit very much depends on what want to do with the extraction. &amp;nbsp;You can also extend memory limit.&lt;/P&gt;&lt;P&gt;If your goal is to return the status of a specific&amp;nbsp;&lt;SPAN&gt;id, say "08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad", you do not have to mvexpand. &amp;nbsp;But search command is inadequate for the job. &amp;nbsp;Do this instead,&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval mystatus = mvindex(status, mvfind(id, "^08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad$"))&lt;/LI-CODE&gt;&lt;P&gt;Unfortunately, this will only return mystatus = "running" becaue mvfind only returns the first matching index. &amp;nbsp;Now, your desired action is&amp;nbsp;&lt;SPAN&gt;to filter by status="Collector is running." &amp;nbsp;This tells me that you are not interested in stateMap, but statusMap. &amp;nbsp;In other words, you expect status of stateMap and statusMap to be distinct, even though both may contain the same id's. (You could have saved volunteers a lot of time by explaining these nuances clearly.) &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;To make this distinction, I'll offer two paths, one also uses regex, the other semantical. &amp;nbsp;First using regex.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=0 "stateMap: \[Map\((?&amp;lt;stateMap&amp;gt;[^\)]+)" ``` not being used ```
| rex field=stateMap max_match=0 "\s*(?&amp;lt;id&amp;gt;\S+) -&amp;gt; (?&amp;lt;state&amp;gt;[^,]+)" ``` not being used ```
| rex max_match=0 "statusMap: \[Map\((?&amp;lt;statusMap&amp;gt;[^\)]+)"
| rex field=statusMap max_match=0 "\s*(?&amp;lt;id&amp;gt;\S+) -&amp;gt; (?&amp;lt;status&amp;gt;[^,]+)"
| eval mystatus = mvindex(status, mvfind(id, "^08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad$"))
| where mystatus == "Collector is running."&lt;/LI-CODE&gt;&lt;P&gt;Second, a semantic extraction&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex max_match=0 "stateMap: \[Map\((?&amp;lt;stateMap&amp;gt;[^\)]+)" ``` not being used ```
| rex max_match=0 "statusMap: \[Map\((?&amp;lt;statusMap&amp;gt;[^\)]+)"
| eval statusMap = mvmap(statusMap, split(statusMap, ", "))
| eval id = mvmap(statusMap, mvindex(split(statusMap, " -&amp;gt; "), 0))
| eval status = mvmap(statusMap, mvindex(split(statusMap, " -&amp;gt; "), 1))
| eval mystatus = mvindex(status, mvfind(id, "^08ff35ad-f7b8-4ef2-bf29-1ccf5e50caad$"))
| where mystatus == "Collector is running."&lt;/LI-CODE&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 11:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636303#M220984</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-03-28T11:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636545#M221062</link>
      <description>&lt;P&gt;any alternate search to change to avoid the error.&lt;/P&gt;&lt;P&gt;to get exact status as above&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;| rex max_match=0 "((\[Map\()|(,\s+))(?&amp;lt;id_status&amp;gt;\w*-\w*-\w*-\w*-\w*\s+-\&amp;gt;\s+[^,\)]*)"
| mvexpand id_status
| rex field=id_status "(?&amp;lt;id&amp;gt;\w*-\w*-\w*-\w*-\w*)\s+-\&amp;gt;\s+(?&amp;lt;status&amp;gt;[^,\)]*)"&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 14:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636545#M221062</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-03-29T14:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636563#M221073</link>
      <description>&lt;P&gt;If you cannot reduce dataset as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;suggested, mvexpand is not suitable. &amp;nbsp;Alternatives see my answer above.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 17:40:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-field-extraction/m-p/636563#M221073</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-03-29T17:40:03Z</dc:date>
    </item>
  </channel>
</rss>

