<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract particular pattern text  from its various possible trailing text pattern? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640044#M221791</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; the runanywhere example works as expected.&lt;/P&gt;&lt;P&gt;Guess I have more pattern which I missed to include and that is returning as well. Hence I updated the runanywhere example as below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval _raw="\"message\":{\"input\":\"192.168.62.10 - - [06/Apr/2023:05:45:51 +0000] \\\"GET /shopping/carts/v1/e5aa581b-ac7a-40f5-a8da-8ab5cb51039c/summary HTTP/1.1\\\" 200 636 8080 13 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/734b2f55-c304-49a5-baa9-8e9994495b55 HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/734b2f55-c304-49a5-baa9-8e9994495b55/product HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\": {\"input\": \"192.168.62.10 - - [15/Apr/2023:03:32:22 +0000] \\\"GET /shopping/carts/v1/152c1299-e598-40d3-8934-29f6662bbb98?productType=ALL HTTP/1.1\\\" 200 1828 8080 13 ms\"}"
| multikv noheader=t
| fields _raw
``` the lines above just set up the example events ```
| rex "\"(?&amp;lt;url&amp;gt;GET /shopping/carts/v1/[^/ ]+\sHTTP)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="super_edition_0-1681531171281.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24927i612D528C497547B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="super_edition_0-1681531171281.png" alt="super_edition_0-1681531171281.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 15 Apr 2023 03:59:41 GMT</pubDate>
    <dc:creator>super_edition</dc:creator>
    <dc:date>2023-04-15T03:59:41Z</dc:date>
    <item>
      <title>How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639925#M221746</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;Below is the set of the log response pattern:&lt;/P&gt;
&lt;P&gt;"message":{"input":"999.111.000.999 - - [06/Apr/2023:05:45:51 +0000] \"GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary HTTP/1.1\" 200 636 8080 13 ms"}&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;"message":{"input":"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \"&lt;FONT color="#FF9900"&gt;&lt;STRONG&gt;GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP&lt;/STRONG&gt;&lt;/FONT&gt;/1.1\" 200 1855 8080 10 ms"}&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;"message":{"input":"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \"GET /shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product HTTP/1.1\" 200 1855 8080 10 ms"}&lt;/P&gt;
&lt;P&gt;"message":{"input":"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \"GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP/1.1\" 200 1855 8080 10 ms"}&lt;/P&gt;
&lt;P&gt;From the above, I am interested to extract only the orange highlighted string eg:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;GET /shopping/carts/v1/&amp;lt;ending with any id alone&amp;gt; HTTP&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I tried with below splunk query as intermediate step to extract the urls:&lt;/P&gt;
&lt;P&gt;index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner | rex field=message.input "(?&amp;lt;servicename&amp;gt;(?:[^\"]|\"\")*HTTP)" | dedup servicename | stats count by servicename&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;servicename&lt;/STRONG&gt; is pre-extracted variable&lt;/P&gt;
&lt;P&gt;But this query returns the all pattern.&lt;/P&gt;
&lt;P&gt;GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary HTTP&lt;BR /&gt;GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;(I need only this)&lt;/STRONG&gt;&lt;BR /&gt;GET /shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product HTTP&lt;BR /&gt;GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP&lt;/P&gt;
&lt;P&gt;Please help&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 16:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639925#M221746</guid>
      <dc:creator>super_edition</dc:creator>
      <dc:date>2023-04-14T16:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting particular pattern text  from its various possible trailing text pattern</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639927#M221748</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "\"(?&amp;lt;url&amp;gt;GET /shopping/carts/v1/[^/ ]+\sHTTP)"&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 14 Apr 2023 09:37:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639927#M221748</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-14T09:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting particular pattern text  from its various possible trailing text pattern</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639929#M221750</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168" target="_blank"&gt;@ITWhisperer&lt;/A&gt;&amp;nbsp; unfortunately it is still returning all patterns:&lt;/P&gt;&lt;P&gt;i&lt;SPAN&gt;ndex=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner&amp;nbsp;| rex "\"(?&amp;lt;url&amp;gt;GET /shopping/carts/v1/[^/ ]+\sHTTP)"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 10:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639929#M221750</guid>
      <dc:creator>super_edition</dc:creator>
      <dc:date>2023-04-14T10:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting particular pattern text  from its various possible trailing text pattern</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639930#M221751</link>
      <description>&lt;P&gt;Interesting! Here is a runanywhere example showing it working.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval _raw="\"message\":{\"input\":\"192.168.62.10 - - [06/Apr/2023:05:45:51 +0000] \\\"GET /shopping/carts/v1/e5aa581b-ac7a-40f5-a8da-8ab5cb51039c/summary HTTP/1.1\\\" 200 636 8080 13 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/734b2f55-c304-49a5-baa9-8e9994495b55 HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/734b2f55-c304-49a5-baa9-8e9994495b55/product HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP/1.1\\\" 200 1855 8080 10 ms\"}"
| multikv noheader=t
| fields _raw
``` the lines above just set up the example events ```
| rex "\"(?&amp;lt;url&amp;gt;GET /shopping/carts/v1/[^/ ]+\sHTTP)"&lt;/LI-CODE&gt;&lt;P&gt;This begs the question, what is it about the events that are being returned which causes them to have the field extracted. Unless you share the actual events, you will have to figure that out for yourself!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 10:06:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/639930#M221751</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-14T10:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640021#M221782</link>
      <description>&lt;P&gt;| rex "GET\s+\/shopping\/carts\/v\d+\/(?&amp;lt;justAcart&amp;gt;[^\/]+)\s+HTTP"&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 21:21:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640021#M221782</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-14T21:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640041#M221790</link>
      <description>&lt;P&gt;I would not invent regex when there are robust, vendor supported ones. &amp;nbsp;Your message.input is a standard access log from NSCA/Apache httpd. &amp;nbsp;So, leverage &lt;A title="Standard transform access-extractions" href="http:/manager/search/data/transforms/extractions/access-extractions?action=edit&amp;amp;ns=system&amp;amp;uri=%2FservicesNS%2Fnobody%2Fsystem%2Fdata%2Ftransforms%2Fextractions%2Faccess-extractions" target="_blank" rel="noopener"&gt;access-extractions&lt;/A&gt; that comes with Splunk itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner
| rename message.input as _raw
| extract access-extractions&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should give you these fields from illustrated data&lt;/P&gt;&lt;TABLE width="2440px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="49.40625px"&gt;bytes&lt;/TD&gt;&lt;TD width="135.515625px"&gt;clientip&lt;/TD&gt;&lt;TD width="40px"&gt;cookie&lt;/TD&gt;&lt;TD width="125.78125px"&gt;file&lt;/TD&gt;&lt;TD width="40px"&gt;ident&lt;/TD&gt;&lt;TD width="40.859375px"&gt;method&lt;/TD&gt;&lt;TD width="145.6875px"&gt;module&lt;/TD&gt;&lt;TD width="52.890625px"&gt;other&lt;/TD&gt;&lt;TD width="40px"&gt;referer&lt;/TD&gt;&lt;TD width="40px"&gt;reference_domain&lt;/TD&gt;&lt;TD width="177.890625px"&gt;reg_time&lt;/TD&gt;&lt;TD width="111.28125px"&gt;requestedPoint&lt;/TD&gt;&lt;TD width="77.375px"&gt;root&lt;/TD&gt;&lt;TD width="40px"&gt;status&lt;/TD&gt;&lt;TD width="441.46875px"&gt;uri&lt;/TD&gt;&lt;TD width="40px"&gt;uri_domain&lt;/TD&gt;&lt;TD width="241.96875px"&gt;uri_path&lt;/TD&gt;&lt;TD width="441.46875px"&gt;uri_query&lt;/TD&gt;&lt;TD width="40px"&gt;user&lt;/TD&gt;&lt;TD width="40px"&gt;useragent&lt;/TD&gt;&lt;TD width="79.171875px"&gt;version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="49.40625px"&gt;636&lt;/TD&gt;&lt;TD width="135.515625px"&gt;999.111.000.999&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="125.78125px"&gt;summary&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40.859375px"&gt;GET&lt;/TD&gt;&lt;TD width="145.6875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="52.890625px"&gt;8080 13 ms&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="177.890625px"&gt;06/Apr/2023:05:45:51 +0000&lt;/TD&gt;&lt;TD width="111.28125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="77.375px"&gt;shopping&lt;/TD&gt;&lt;TD width="40px"&gt;200&lt;/TD&gt;&lt;TD width="441.46875px"&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="241.96875px"&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary&lt;/TD&gt;&lt;TD width="441.46875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="79.171875px"&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="49.40625px"&gt;1855&lt;/TD&gt;&lt;TD width="135.515625px"&gt;999.111.000.999&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="125.78125px"&gt;83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40.859375px"&gt;GET&lt;/TD&gt;&lt;TD width="145.6875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="52.890625px"&gt;8080 10 ms&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="177.890625px"&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD width="111.28125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="77.375px"&gt;shopping&lt;/TD&gt;&lt;TD width="40px"&gt;200&lt;/TD&gt;&lt;TD width="441.46875px"&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="241.96875px"&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD width="441.46875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="79.171875px"&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="49.40625px"&gt;1855&lt;/TD&gt;&lt;TD width="135.515625px"&gt;999.111.000.999&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="125.78125px"&gt;product&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40.859375px"&gt;GET&lt;/TD&gt;&lt;TD width="145.6875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="52.890625px"&gt;8080 10 ms&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="177.890625px"&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD width="111.28125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="77.375px"&gt;shopping&lt;/TD&gt;&lt;TD width="40px"&gt;200&lt;/TD&gt;&lt;TD width="441.46875px"&gt;/shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="241.96875px"&gt;/shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product&lt;/TD&gt;&lt;TD width="441.46875px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="79.171875px"&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="49.40625px"&gt;1855&lt;/TD&gt;&lt;TD width="135.515625px"&gt;999.111.000.999&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="125.78125px"&gt;CJS&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40.859375px"&gt;GET&lt;/TD&gt;&lt;TD width="145.6875px"&gt;ONLINE_BOOKING&lt;/TD&gt;&lt;TD width="52.890625px"&gt;8080 10 ms&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="177.890625px"&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD width="111.28125px"&gt;DESTINATION&lt;/TD&gt;&lt;TD width="77.375px"&gt;location-context&lt;/TD&gt;&lt;TD width="40px"&gt;200&lt;/TD&gt;&lt;TD width="441.46875px"&gt;/location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="241.96875px"&gt;/location-context/stations/v1/CJS&lt;/TD&gt;&lt;TD width="441.46875px"&gt;module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION&lt;/TD&gt;&lt;TD width="40px"&gt;-&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="79.171875px"&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;What you are saying is that you only want method + uri_path + version for some select events. &amp;nbsp;So, work from these extracted fields and build what you asked for. &amp;nbsp;BTW, you should eliminate those that don't contain shopping carts first. &amp;nbsp;So, that's how I built it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner "GET /shopping/carts/"
| rename _raw AS temp, message.input AS _raw ``` in case original _raw is needed later ```
| extract access-extractions
| where mvcount(split(uri_path, "/")) = 5
| eval ask = method . " " . uri_path . " " . mvindex(split(version, "/"), 0)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note the final string in the above concatenation could as well be "HTTP". &amp;nbsp;But I want to highlight how unusual it is to want the string HTTP without actual version, because HTTP version makes a difference in applications. &amp;nbsp;Anyway, using your illustrated data, my emulation gives&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ask&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is my emulation that you can play and compare with real data&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval data = split("{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:05:45:51 +0000] \\\"GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary HTTP/1.1\\\" 200 636 8080 13 ms\"}}
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP/1.1\\\" 200 1855 8080 10 ms\"}}
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product HTTP/1.1\\\" 200 1855 8080 10 ms\"}{
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP/1.1\\\" 200 1855 8080 10 ms\"}}", "
")
| mvexpand data
| spath input=data
| fields - _time data
| rename message.input as _raw
| search "GET /shopping/carts/"
``` the agove emulates search
index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner "GET /shopping/carts/"```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 03:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640041#M221790</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-04-15T03:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640044#M221791</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; the runanywhere example works as expected.&lt;/P&gt;&lt;P&gt;Guess I have more pattern which I missed to include and that is returning as well. Hence I updated the runanywhere example as below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval _raw="\"message\":{\"input\":\"192.168.62.10 - - [06/Apr/2023:05:45:51 +0000] \\\"GET /shopping/carts/v1/e5aa581b-ac7a-40f5-a8da-8ab5cb51039c/summary HTTP/1.1\\\" 200 636 8080 13 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/734b2f55-c304-49a5-baa9-8e9994495b55 HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/734b2f55-c304-49a5-baa9-8e9994495b55/product HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\":{\"input\":\"192.168.54.47 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP/1.1\\\" 200 1855 8080 10 ms\"}
\"message\": {\"input\": \"192.168.62.10 - - [15/Apr/2023:03:32:22 +0000] \\\"GET /shopping/carts/v1/152c1299-e598-40d3-8934-29f6662bbb98?productType=ALL HTTP/1.1\\\" 200 1828 8080 13 ms\"}"
| multikv noheader=t
| fields _raw
``` the lines above just set up the example events ```
| rex "\"(?&amp;lt;url&amp;gt;GET /shopping/carts/v1/[^/ ]+\sHTTP)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="super_edition_0-1681531171281.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24927i612D528C497547B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="super_edition_0-1681531171281.png" alt="super_edition_0-1681531171281.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 03:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640044#M221791</guid>
      <dc:creator>super_edition</dc:creator>
      <dc:date>2023-04-15T03:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640047#M221793</link>
      <description>&lt;P&gt;(Somehow my previous rely was lost.) I try not to reinvent regex if there exists robust, vendor supported options. &amp;nbsp;For message.input, it is standard NCSA/Apache access log. &amp;nbsp;Splunk provides several built-in standard extractions. &amp;nbsp;I'll use&amp;nbsp;&lt;A href="http:/manager/search/data/transforms/extractions/access-extractions?action=edit&amp;amp;ns=system&amp;amp;uri=%2FservicesNS%2Fnobody%2Fsystem%2Fdata%2Ftransforms%2Fextractions%2Faccess-extractions" target="_blank" rel="noopener"&gt;access-extractions&lt;/A&gt;&amp;nbsp;as example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner
| rename _raw as temp, message.input as _raw
| extract access-extractions&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will give you&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;bytes&lt;/TD&gt;&lt;TD&gt;clientip&lt;/TD&gt;&lt;TD&gt;cookie&lt;/TD&gt;&lt;TD&gt;file&lt;/TD&gt;&lt;TD&gt;ident&lt;/TD&gt;&lt;TD&gt;method&lt;/TD&gt;&lt;TD&gt;module&lt;/TD&gt;&lt;TD&gt;other&lt;/TD&gt;&lt;TD&gt;referer&lt;/TD&gt;&lt;TD&gt;referer_domain&lt;/TD&gt;&lt;TD&gt;req_time&lt;/TD&gt;&lt;TD&gt;requestedPoint&lt;/TD&gt;&lt;TD&gt;root&lt;/TD&gt;&lt;TD&gt;status&lt;/TD&gt;&lt;TD&gt;uri&lt;/TD&gt;&lt;TD&gt;uri_domain&lt;/TD&gt;&lt;TD&gt;uri_path&lt;/TD&gt;&lt;TD&gt;uri_query&lt;/TD&gt;&lt;TD&gt;user&lt;/TD&gt;&lt;TD&gt;useragent&lt;/TD&gt;&lt;TD&gt;version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;636&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;summary&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;8080 13 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:05:45:51 +0000&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;shopping&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1855&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;8080 10 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;shopping&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1855&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;product&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;8080 10 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;shopping&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1855&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;CJS&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;ONLINE_BOOKING&lt;/TD&gt;&lt;TD&gt;8080 10 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD&gt;DESTINATION&lt;/TD&gt;&lt;TD&gt;location-context&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/location-context/stations/v1/CJS&lt;/TD&gt;&lt;TD&gt;module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;So, your ask is to get method + uri_path + version for select events. &amp;nbsp;Speaking of select, you should do the selection in the main search. &amp;nbsp;That's why the following code adds /shopping/carts/.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner
"GET /shopping/carts/"
| extract access-extractions
| where mvcount(split(uri_path, "/")) = 5 ``` nothing after cart ID ```
| eval ask = method . " " . uri_path . " " . mvindex(split(version, "/"), 0)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;The end result, of course, is&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ask&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Obviously, the final segment of the concatenation above could as well be hard coded "HTTP". &amp;nbsp;But I wanted to highlight how unusual it is to just take the protocol without actual version, because version makes a difference in applications.&lt;/P&gt;&lt;P&gt;Anyway, the following is an emulation that you can play and compare with real data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval data = split("{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:05:45:51 +0000] \\\"GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary HTTP/1.1\\\" 200 636 8080 13 ms\"}}
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP/1.1\\\" 200 1855 8080 10 ms\"}}
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product HTTP/1.1\\\" 200 1855 8080 10 ms\"}{
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP/1.1\\\" 200 1855 8080 10 ms\"}}", "
")
| mvexpand data
| spath input=data
``` the agove emulates search
index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner```
| where match('message.input', "GET /shopping/carts/")
``` the agove emulates search
index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner "GET /shopping/carts/"```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 04:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640047#M221793</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-04-15T04:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640048#M221794</link>
      <description>&lt;P&gt;(Somehow my previous rely was lost.) I try not to reinvent regex if there exists robust, vendor supported options. &amp;nbsp;For message.input, it is standard NCSA/Apache access log. &amp;nbsp;Splunk provides several built-in standard extractions. &amp;nbsp;I'll use&amp;nbsp;&lt;A href="http:/manager/search/data/transforms/extractions/access-extractions?action=edit&amp;amp;ns=system&amp;amp;uri=%2FservicesNS%2Fnobody%2Fsystem%2Fdata%2Ftransforms%2Fextractions%2Faccess-extractions" target="_blank" rel="noopener"&gt;access-extractions&lt;/A&gt;&amp;nbsp;as example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner
| rename _raw as temp, message.input as _raw
| extract access-extractions&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will give you&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;bytes&lt;/TD&gt;&lt;TD&gt;clientip&lt;/TD&gt;&lt;TD&gt;cookie&lt;/TD&gt;&lt;TD&gt;file&lt;/TD&gt;&lt;TD&gt;ident&lt;/TD&gt;&lt;TD&gt;method&lt;/TD&gt;&lt;TD&gt;module&lt;/TD&gt;&lt;TD&gt;other&lt;/TD&gt;&lt;TD&gt;referer&lt;/TD&gt;&lt;TD&gt;referer_domain&lt;/TD&gt;&lt;TD&gt;req_time&lt;/TD&gt;&lt;TD&gt;requestedPoint&lt;/TD&gt;&lt;TD&gt;root&lt;/TD&gt;&lt;TD&gt;status&lt;/TD&gt;&lt;TD&gt;uri&lt;/TD&gt;&lt;TD&gt;uri_domain&lt;/TD&gt;&lt;TD&gt;uri_path&lt;/TD&gt;&lt;TD&gt;uri_query&lt;/TD&gt;&lt;TD&gt;user&lt;/TD&gt;&lt;TD&gt;useragent&lt;/TD&gt;&lt;TD&gt;version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;636&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;summary&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;8080 13 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:05:45:51 +0000&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;shopping&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1855&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;8080 10 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;shopping&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1855&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;product&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;8080 10 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;shopping&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1855&lt;/TD&gt;&lt;TD&gt;999.111.000.999&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;CJS&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;GET&lt;/TD&gt;&lt;TD&gt;ONLINE_BOOKING&lt;/TD&gt;&lt;TD&gt;8080 10 ms&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;06/Apr/2023:04:08:13 +0000&lt;/TD&gt;&lt;TD&gt;DESTINATION&lt;/TD&gt;&lt;TD&gt;location-context&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;/location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;/location-context/stations/v1/CJS&lt;/TD&gt;&lt;TD&gt;module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;HTTP/1.1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;So, your ask is to get method + uri_path + version for select events. &amp;nbsp;Speaking of select, you should do the selection in the main search. &amp;nbsp;That's why the following code adds /shopping/carts/.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner
"GET /shopping/carts/"
| extract access-extractions
| where mvcount(split(uri_path, "/")) = 5 ``` nothing after cart ID ```
| eval ask = method . " " . uri_path . " " . mvindex(split(version, "/"), 0)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The end result, of course, is&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ask&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Obviously, the final segment of the concatenation above could as well be hard coded "HTTP". &amp;nbsp;But I wanted to highlight how unusual it is to just take the protocol without actual version, because version makes a difference in applications.&lt;/P&gt;&lt;P&gt;Anyway, the following is an emulation that you can play and compare with real data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval data = split("{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:05:45:51 +0000] \\\"GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d/summary HTTP/1.1\\\" 200 636 8080 13 ms\"}}
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/83h3h331-g494-28h4-yyw7-dq123123123d HTTP/1.1\\\" 200 1855 8080 10 ms\"}}
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /shopping/carts/v1/73737373-j3j3-8djd-jdjd-kejdjehi3nej/product HTTP/1.1\\\" 200 1855 8080 10 ms\"}{
{\"message\":{\"input\":\"999.111.000.999 - - [06/Apr/2023:04:08:13 +0000] \\\"GET /location-context/stations/v1/CJS?module=ONLINE_BOOKING&amp;amp;requestedPoint=DESTINATION HTTP/1.1\\\" 200 1855 8080 10 ms\"}}", "
")
| mvexpand data
| spath input=data
``` the agove emulates search
index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner```
| where match('message.input', "GET /shopping/carts/")
``` the agove emulates search
index=my_index openshift_cluster="cluster009" sourcetype=openshift_logs openshift_namespace=my_ns openshift_container_name=contaner "GET /shopping/carts/"```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 04:52:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640048#M221794</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-04-15T04:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640067#M221796</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\"(?&amp;lt;url&amp;gt;GET /shopping/carts/v1/[^/ ?]+\sHTTP)"&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 15 Apr 2023 08:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640067#M221796</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-15T08:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract particular pattern text  from its various possible trailing text pattern?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640082#M221807</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; - Thanks.&amp;nbsp; It is now returning the expected pattern alone.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 11:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-particular-pattern-text-from-its-various-possible/m-p/640082#M221807</guid>
      <dc:creator>super_edition</dc:creator>
      <dc:date>2023-04-15T11:33:51Z</dc:date>
    </item>
  </channel>
</rss>

