<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to separate OS name and OS version values from a field having combined value? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-OS-name-and-OS-version-values-from-a-field/m-p/639522#M221589</link>
    <description>&lt;P&gt;I have a column that holds OS Name along with it's version details.&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="474"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="474"&gt;os_full_name&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.1.1503 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.2.1511 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.4.1708 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Fire Linux OS 6.2.0-42&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2008 R2 Enterprise Version 6.1.7601 Build 7601&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Datacenter Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Standard Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2016&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.9 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 11 (x86_64) VERSION = 11 PATCHLEVEL = 4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 12 (x86_64) VERSION = 12 PATCHLEVEL = 3&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 14.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;VMware ESXi vmnix-x86 5.5.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to split this column so that I get OS name and Version details in separate fields to get something like -&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="964"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="474"&gt;os_full_name&lt;/TD&gt;
&lt;TD width="298"&gt;os_name&lt;/TD&gt;
&lt;TD width="192"&gt;os_version&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.1.1503 (Core)&lt;/TD&gt;
&lt;TD&gt;CentOS Linux&lt;/TD&gt;
&lt;TD&gt;release 7.1.1503 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.2.1511 (Core)&lt;/TD&gt;
&lt;TD&gt;CentOS Linux&lt;/TD&gt;
&lt;TD&gt;release 7.2.1511 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.4.1708 (Core)&lt;/TD&gt;
&lt;TD&gt;CentOS Linux&lt;/TD&gt;
&lt;TD&gt;release 7.4.1708 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Fire Linux OS 6.2.0-42&lt;/TD&gt;
&lt;TD&gt;Fire Linux OS&lt;/TD&gt;
&lt;TD&gt;6.2.0-42&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2008 R2 Enterprise Version 6.1.7601 Build 7601&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2008 R2 Enterprise&lt;/TD&gt;
&lt;TD&gt;Version 6.1.7601 Build 7601&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Datacenter Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Datacenter&lt;/TD&gt;
&lt;TD&gt;Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Standard Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Standard&lt;/TD&gt;
&lt;TD&gt;Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2016&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2016&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;/TD&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server&lt;/TD&gt;
&lt;TD&gt;release 6.3 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.9 (Santiago)&lt;/TD&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server&lt;/TD&gt;
&lt;TD&gt;release 6.9 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 11 (x86_64) VERSION = 11 PATCHLEVEL = 4&lt;/TD&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 11 (x86_64)&lt;/TD&gt;
&lt;TD&gt;VERSION = 11 PATCHLEVEL = 4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 12 (x86_64) VERSION = 12 PATCHLEVEL = 3&lt;/TD&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 12 (x86_64)&lt;/TD&gt;
&lt;TD&gt;VERSION = 12 PATCHLEVEL = 3&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 14.04.3 LTS&lt;/TD&gt;
&lt;TD&gt;Ubuntu&lt;/TD&gt;
&lt;TD&gt;14.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04 LTS&lt;/TD&gt;
&lt;TD&gt;Ubuntu&lt;/TD&gt;
&lt;TD&gt;16.04 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04.3 LTS&lt;/TD&gt;
&lt;TD&gt;Ubuntu&lt;/TD&gt;
&lt;TD&gt;16.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;VMware ESXi vmnix-x86 5.5.0&lt;/TD&gt;
&lt;TD&gt;VMware ESXi&lt;/TD&gt;
&lt;TD&gt;vmnix-x86 5.5.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone please help with this?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 16:30:46 GMT</pubDate>
    <dc:creator>sh254087</dc:creator>
    <dc:date>2023-04-11T16:30:46Z</dc:date>
    <item>
      <title>How to separate OS name and OS version values from a field having combined value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-OS-name-and-OS-version-values-from-a-field/m-p/639522#M221589</link>
      <description>&lt;P&gt;I have a column that holds OS Name along with it's version details.&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="474"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="474"&gt;os_full_name&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.1.1503 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.2.1511 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.4.1708 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Fire Linux OS 6.2.0-42&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2008 R2 Enterprise Version 6.1.7601 Build 7601&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Datacenter Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Standard Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2016&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.9 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 11 (x86_64) VERSION = 11 PATCHLEVEL = 4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 12 (x86_64) VERSION = 12 PATCHLEVEL = 3&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 14.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;VMware ESXi vmnix-x86 5.5.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to split this column so that I get OS name and Version details in separate fields to get something like -&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="964"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="474"&gt;os_full_name&lt;/TD&gt;
&lt;TD width="298"&gt;os_name&lt;/TD&gt;
&lt;TD width="192"&gt;os_version&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.1.1503 (Core)&lt;/TD&gt;
&lt;TD&gt;CentOS Linux&lt;/TD&gt;
&lt;TD&gt;release 7.1.1503 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.2.1511 (Core)&lt;/TD&gt;
&lt;TD&gt;CentOS Linux&lt;/TD&gt;
&lt;TD&gt;release 7.2.1511 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;CentOS Linux release 7.4.1708 (Core)&lt;/TD&gt;
&lt;TD&gt;CentOS Linux&lt;/TD&gt;
&lt;TD&gt;release 7.4.1708 (Core)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Fire Linux OS 6.2.0-42&lt;/TD&gt;
&lt;TD&gt;Fire Linux OS&lt;/TD&gt;
&lt;TD&gt;6.2.0-42&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2008 R2 Enterprise Version 6.1.7601 Build 7601&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2008 R2 Enterprise&lt;/TD&gt;
&lt;TD&gt;Version 6.1.7601 Build 7601&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Datacenter Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Datacenter&lt;/TD&gt;
&lt;TD&gt;Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Standard Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2012 R2 Standard&lt;/TD&gt;
&lt;TD&gt;Version 6.3.9600 Build 9600&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Microsoft Windows Server 2016&lt;/TD&gt;
&lt;TD&gt;Microsoft Windows Server 2016&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;/TD&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server&lt;/TD&gt;
&lt;TD&gt;release 6.3 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server release 6.9 (Santiago)&lt;/TD&gt;
&lt;TD&gt;Red Hat Enterprise Linux Server&lt;/TD&gt;
&lt;TD&gt;release 6.9 (Santiago)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 11 (x86_64) VERSION = 11 PATCHLEVEL = 4&lt;/TD&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 11 (x86_64)&lt;/TD&gt;
&lt;TD&gt;VERSION = 11 PATCHLEVEL = 4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 12 (x86_64) VERSION = 12 PATCHLEVEL = 3&lt;/TD&gt;
&lt;TD&gt;SUSE Linux Enterprise Server 12 (x86_64)&lt;/TD&gt;
&lt;TD&gt;VERSION = 12 PATCHLEVEL = 3&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 14.04.3 LTS&lt;/TD&gt;
&lt;TD&gt;Ubuntu&lt;/TD&gt;
&lt;TD&gt;14.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04 LTS&lt;/TD&gt;
&lt;TD&gt;Ubuntu&lt;/TD&gt;
&lt;TD&gt;16.04 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ubuntu 16.04.3 LTS&lt;/TD&gt;
&lt;TD&gt;Ubuntu&lt;/TD&gt;
&lt;TD&gt;16.04.3 LTS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;VMware ESXi vmnix-x86 5.5.0&lt;/TD&gt;
&lt;TD&gt;VMware ESXi&lt;/TD&gt;
&lt;TD&gt;vmnix-x86 5.5.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone please help with this?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 16:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-OS-name-and-OS-version-values-from-a-field/m-p/639522#M221589</guid>
      <dc:creator>sh254087</dc:creator>
      <dc:date>2023-04-11T16:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate OS name and OS version values from a field having combined value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-OS-name-and-OS-version-values-from-a-field/m-p/639525#M221590</link>
      <description>&lt;P&gt;OS names and versions don't follow a universal pattern, so you could do multiple rex matches&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?&amp;lt;os_name&amp;gt;CentOS Linux)\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;Fire Linux OS)\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;Microsoft Windows Server 2008 R2 Enterprise)\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;Microsoft Windows Server 2012 R2 Datacenter)\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;Microsoft Windows Server 2012 R2 Standard)\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;Red Hat Enterprise Linux Server)\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;SUSE Linux Enterprise Server 11 (x86_64))\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;SUSE Linux Enterprise Server 12 (x86_64))\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;Ubuntu)\s(?&amp;lt;os_version&amp;gt;.*)"
| rex "(?&amp;lt;os_name&amp;gt;VMware ESXi)\s(?&amp;lt;os_version&amp;gt;.*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 11 Apr 2023 16:15:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-OS-name-and-OS-version-values-from-a-field/m-p/639525#M221590</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-11T16:15:45Z</dc:date>
    </item>
  </channel>
</rss>

