<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex field extraction repeating string in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-help-me-adjust-my-regex-to-only-capture-quot-P3820/m-p/645692#M223570</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225681"&gt;@michaeler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Here's a regex to extract everything up to the first " - 1339Z" (any numbers will match)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=rows "(?&amp;lt;Details&amp;gt;.+?)\s-\s\d{4}Z"&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Here's a query to test it out:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval rows="P3820 Houston to A345 Atlanta Line Down - 1339Z 19 May - On-going - TKT39390423@P3820 Houston to A345 Atlanta Line Down - 1339Z 19 May - 0834Z 20 May - TKT39390423@P3820 Houston to A345 Atlanta Line Down - 1339Z 19 MAY - Ongoing - TKT39390423 - 1339Z 19 May - On-going - TKT39390423@P3820 Houston - A345 Atlanta Line Down - 1339Z 19 MAY - Ongoing - INC39390423, DIRJ LLO MM#:394039 - 1339Z 19 May - On-going - TKT39390423@P3820 Houston - A345 Atlanta Line Down - 1339Z 19 MAY - 1834Z MAY - INC39390423, DIRJ LLO MM#:394039 - 1339Z 19 May - 0834Z 20 May - TKT39390423"
| makemv rows delim="@"
| mvexpand rows
| table rows
| rex field=rows "(?&amp;lt;Details&amp;gt;.+?)\s-\s\d{4}Z"&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="danspav_2-1685930189341.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25683i6D95933E7172CB9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="danspav_2-1685930189341.png" alt="danspav_2-1685930189341.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Daniel&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jun 2023 02:03:08 GMT</pubDate>
    <dc:creator>danspav</dc:creator>
    <dc:date>2023-06-05T02:03:08Z</dc:date>
    <item>
      <title>Can someone help me adjust my regex to only capture "P3820 Houston to A345 Atlanta Line Down" for the field "Details"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-help-me-adjust-my-regex-to-only-capture-quot-P3820/m-p/644317#M223171</link>
      <description>&lt;P&gt;I can't use the field extractor because the field configurations are frequently very different and it gives me errors so I've been using "| rex" instead.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone help me adjust my regex to only capture&amp;nbsp;"&lt;SPAN&gt;P3820&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Houston&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;A&lt;/SPAN&gt;&lt;SPAN&gt;345&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Atlanta Line&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Down" for the field "Details" every time?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;| rex field= "&lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;?&amp;lt;Details&amp;gt;.*&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s\d&lt;/SPAN&gt;&lt;SPAN class=""&gt;{4}&lt;/SPAN&gt;&lt;SPAN class=""&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;Z&lt;/SPAN&gt;&lt;SPAN class=""&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s\d&lt;/SPAN&gt;&lt;SPAN class=""&gt;{2}&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s&lt;/SPAN&gt;&lt;SPAN class=""&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;a&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;zA&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;Z&lt;/SPAN&gt;&lt;SPAN class=""&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;{3}&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s&lt;/SPAN&gt;&lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;\d&lt;/SPAN&gt;&lt;SPAN class=""&gt;{4}&lt;/SPAN&gt;&lt;SPAN class=""&gt;Z&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s\d&lt;/SPAN&gt;&lt;SPAN class=""&gt;{2}&lt;/SPAN&gt;&lt;SPAN class=""&gt;\s&lt;/SPAN&gt;&lt;SPAN class=""&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;a&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;zA&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;Z&lt;/SPAN&gt;&lt;SPAN class=""&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;{3}&lt;/SPAN&gt;&lt;SPAN class=""&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;On&lt;/SPAN&gt;&lt;SPAN class=""&gt;)"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;field examples:&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;P3820&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Houston&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;A&lt;/SPAN&gt;&lt;SPAN&gt;345&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Atlanta Line&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Down&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;1&lt;/SPAN&gt;&lt;SPAN&gt;339Z&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;19&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;On-going&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;TKT39390423&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;P3820&amp;nbsp;Houston&amp;nbsp;to&amp;nbsp;A345&amp;nbsp;Atlanta Line&amp;nbsp;Down&amp;nbsp;-&amp;nbsp;1339Z&amp;nbsp;19&amp;nbsp;May&amp;nbsp;- 0834Z 20 May -&amp;nbsp;TKT39390423&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;P3820&amp;nbsp;Houston to&amp;nbsp;A345&amp;nbsp;Atlanta Line&amp;nbsp;Down -&amp;nbsp;1339Z 19 MAY - Ongoing - TKT39390423 - 1339Z&amp;nbsp;19&amp;nbsp;May&amp;nbsp;-&amp;nbsp;On-going&amp;nbsp;-&amp;nbsp;TKT39390423&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;P3820&amp;nbsp;Houston&amp;nbsp;-&amp;nbsp;A345&amp;nbsp;Atlanta Line&amp;nbsp;Down&amp;nbsp;-&amp;nbsp;1339Z&amp;nbsp;19&amp;nbsp;MAY - Ongoing - INC39390423, DIRJ LLO MM#:394039 - 1339Z&amp;nbsp;19&amp;nbsp;May&amp;nbsp;-&amp;nbsp;On-going&amp;nbsp;-&amp;nbsp;TKT39390423&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;P3820&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Houston&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;A&lt;/SPAN&gt;&lt;SPAN&gt;345&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Atlanta&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Line&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Down&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;1&lt;/SPAN&gt;&lt;SPAN&gt;339Z&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;19&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;MAY&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;1834Z MAY&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;INC39390423,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;DIRJ&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;LLO&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;MM#:394039&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;339Z&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;19&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;0834Z 20 May&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;TKT39390423&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I don't have any issue for the first two but when the date/time range is repeated I end up with everything before the second&amp;nbsp; "1339Z&amp;nbsp;19&amp;nbsp;May" included in the "Details" field&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 14:18:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-help-me-adjust-my-regex-to-only-capture-quot-P3820/m-p/644317#M223171</guid>
      <dc:creator>michaeler</dc:creator>
      <dc:date>2023-06-05T14:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Regex field extraction repeating string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-help-me-adjust-my-regex-to-only-capture-quot-P3820/m-p/645692#M223570</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225681"&gt;@michaeler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Here's a regex to extract everything up to the first " - 1339Z" (any numbers will match)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=rows "(?&amp;lt;Details&amp;gt;.+?)\s-\s\d{4}Z"&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Here's a query to test it out:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval rows="P3820 Houston to A345 Atlanta Line Down - 1339Z 19 May - On-going - TKT39390423@P3820 Houston to A345 Atlanta Line Down - 1339Z 19 May - 0834Z 20 May - TKT39390423@P3820 Houston to A345 Atlanta Line Down - 1339Z 19 MAY - Ongoing - TKT39390423 - 1339Z 19 May - On-going - TKT39390423@P3820 Houston - A345 Atlanta Line Down - 1339Z 19 MAY - Ongoing - INC39390423, DIRJ LLO MM#:394039 - 1339Z 19 May - On-going - TKT39390423@P3820 Houston - A345 Atlanta Line Down - 1339Z 19 MAY - 1834Z MAY - INC39390423, DIRJ LLO MM#:394039 - 1339Z 19 May - 0834Z 20 May - TKT39390423"
| makemv rows delim="@"
| mvexpand rows
| table rows
| rex field=rows "(?&amp;lt;Details&amp;gt;.+?)\s-\s\d{4}Z"&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="danspav_2-1685930189341.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25683i6D95933E7172CB9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="danspav_2-1685930189341.png" alt="danspav_2-1685930189341.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 02:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-help-me-adjust-my-regex-to-only-capture-quot-P3820/m-p/645692#M223570</guid>
      <dc:creator>danspav</dc:creator>
      <dc:date>2023-06-05T02:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Regex field extraction repeating string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-someone-help-me-adjust-my-regex-to-only-capture-quot-P3820/m-p/645730#M223584</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;a good tool to create a regex is regex101.com. You could create regex here and see immediately how it works. If there is something which you cannot solve by yourself, you could save it and share that link to another people to help you.&amp;nbsp;&lt;A href="https://regex101.com/r/H9vuAk/1" target="_blank"&gt;https://regex101.com/r/H9vuAk/1&lt;/A&gt;&amp;nbsp;here is your sample and how it was handled with PCRE2 engine. As you see it match more than splunk rex as default max_match=1. In splunk this is working as normally rex match only first one. But time by time you need to use max_match=0 and then it didn't work. But if you add ^ into first character then it work and actually it's little bit efficient than without it (&lt;A href="https://regex101.com/r/fD0J9e/1" target="_blank"&gt;https://regex101.com/r/fD0J9e/1&lt;/A&gt;).&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 09:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-someone-help-me-adjust-my-regex-to-only-capture-quot-P3820/m-p/645730#M223584</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-05T09:06:49Z</dc:date>
    </item>
  </channel>
</rss>

