<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Help in extraction of multiple file names from an event and add it as a separate field using rex command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646965#M223932</link>
    <description>&lt;P&gt;HI IT Whisperer,&lt;/P&gt;&lt;P&gt;Thanks for your response. As mentioned by you, below is the raw event.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{"&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;2023-06-13T09:35:27.498033Z&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;level&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;filename&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;splunk_sample_csv.py&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;funcName&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;main&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;lineno&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;38&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;message&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;Dataframe&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;row&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;_c0\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;0\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;1\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"Timestamp\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"2023\\/06\\/13&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;11:22:45\\\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"status\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"files&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;arrived&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;\\\&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;3\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"files\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;4\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220221.ok\\\"\",\"5\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_UBER_DWH2_D20220221.ok\\\"\",\"6\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file1.txt.ok\\\"\",\"7\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file2.txt.ok\\\"\",\"8\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file3.txt.ok\\\"\",\"9\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220412.ok\\\"\",\"10\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220420.ok\\\"\",\"11\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211223.ok\\\"\",\"12\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211224.ok\\\"\",\"13\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211225.ok\\\"\",\"14\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"NOSPKP2P_DLY_NOK_D230708.ok\\\"\",\"15\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"DUMMY_DLY_NOK_D230613.ok\\\"\",\"16\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"DUMMY_TEST_DLY_NOK_D230613.ok\\\"\",\"17\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_12.ok\\\"\",\"18\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_152.ok\\\"\",\"19\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_2023-04-19-04.04.32.679000.csv.ok\\\"\",\"20\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_2023-04-20-05.09.39.679000.csv.ok\\\"\",\"21\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_2023-04-18-05.09.39.679000.csv.ok\\\"\",\"22\":\&lt;/A&gt;&lt;/SPAN&gt;" ]&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;23\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"}&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"}} ", "&lt;SPAN class=""&gt;process&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;32633&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;processName&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;MainProcess&lt;/SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to extract the file names like&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;PAKS_FACT_DWH2_D20220221.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;PAKS_UBER_DWH2_D20220221.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;HHE_SIT_check_file1.txt.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;HHE_SIT_check_file2.txt.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;HHE_SIT_check_file3.txt.ok &lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;separately and add them as a separate field using the below query&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;index= app_events_dwh2_de_int | rex max_match=0 "\\\\\\\\\\\\\"files\\\\\\\\\\\\\":\s*\\\\\\\\\\\\\"(?&amp;lt;File_Arrived&amp;gt;[^\\\]+)"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;but this doesn't worked. Please help us on this issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jun 2023 12:20:34 GMT</pubDate>
    <dc:creator>Renunaren</dc:creator>
    <dc:date>2023-06-14T12:20:34Z</dc:date>
    <item>
      <title>How can I extract multiple file names from an event and add it as a separate field using rex command?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646957#M223926</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We have a raw event where the message field consists of multiple file names, we want to extract those and add them as a separate field. Please help us on this. Below is the sample event for reference.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;{"&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;2023-06-13T09:35:27.498033Z&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;level&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;filename&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;splunk_sample_csv.py&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;funcName&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;main&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;lineno&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;38&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;message&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;Dataframe&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;row&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;_c0\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;0\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;1\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"Timestamp\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"2023\\/06\\/13&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;11:22:45\\\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"status\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"files&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;arrived&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;\\\&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;3\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"files\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;4\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220221.ok\\\"\",\"5\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_UBER_DWH2_D20220221.ok\\\"\",\"6\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file1.txt.ok\\\"\",\"7\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file2.txt.ok\\\"\",\"8\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file3.txt.ok\\\"\",\"9\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220412.ok\\\"\",\"10\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220420.ok\\\"\",\"11\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211223.ok\\\"\",\"12\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211224.ok\\\"\",\"13\":\&lt;/A&gt;&lt;/SPAN&gt;" ]&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;23\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"}&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"}} ", "&lt;SPAN class=""&gt;process&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;32633&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;processName&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;MainProcess&lt;/SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Below is the sample SPL command used for this purpose.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;index= app_events_dwh2_de_int | rex max_match=0 "\\\\\\\\\\\\\"files\\\\\\\\\\\\\":\s*\\\\\\\\\\\\\"(?&amp;lt;File_Arrived&amp;gt;[^\\\]+)"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help us on this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 20:20:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646957#M223926</guid>
      <dc:creator>Renunaren</dc:creator>
      <dc:date>2023-06-15T20:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extraction of multiple file names from an event and add it as a separate field using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646959#M223928</link>
      <description>&lt;P&gt;Please repost your raw event in a code block &amp;lt;/&amp;gt; so that it doesn't get corrupted by formatting&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 11:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646959#M223928</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-14T11:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extraction of multiple file names from an event and add it as a separate field using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646965#M223932</link>
      <description>&lt;P&gt;HI IT Whisperer,&lt;/P&gt;&lt;P&gt;Thanks for your response. As mentioned by you, below is the raw event.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;{"&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;2023-06-13T09:35:27.498033Z&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;level&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;filename&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;splunk_sample_csv.py&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;funcName&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;main&lt;/SPAN&gt;", "&lt;SPAN class=""&gt;lineno&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;38&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;message&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;Dataframe&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;row&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;_c0\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;0\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"{&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;1\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"Timestamp\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"2023\\/06\\/13&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;11:22:45\\\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;2\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"status\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"files&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;arrived&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;\\\&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;3\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"files\\\&lt;/A&gt;&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;4\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220221.ok\\\"\",\"5\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_UBER_DWH2_D20220221.ok\\\"\",\"6\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file1.txt.ok\\\"\",\"7\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file2.txt.ok\\\"\",\"8\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"HHE_SIT_check_file3.txt.ok\\\"\",\"9\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220412.ok\\\"\",\"10\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20220420.ok\\\"\",\"11\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211223.ok\\\"\",\"12\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211224.ok\\\"\",\"13\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"PAKS_FACT_DWH2_D20211225.ok\\\"\",\"14\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"NOSPKP2P_DLY_NOK_D230708.ok\\\"\",\"15\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"DUMMY_DLY_NOK_D230613.ok\\\"\",\"16\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"DUMMY_TEST_DLY_NOK_D230613.ok\\\"\",\"17\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_12.ok\\\"\",\"18\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_152.ok\\\"\",\"19\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_2023-04-19-04.04.32.679000.csv.ok\\\"\",\"20\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_2023-04-20-05.09.39.679000.csv.ok\\\"\",\"21\":\&lt;/A&gt;&lt;/SPAN&gt;"&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;\\\"TLX2DB.PROVD.DREAM_2023-04-18-05.09.39.679000.csv.ok\\\"\",\"22\":\&lt;/A&gt;&lt;/SPAN&gt;" ]&lt;SPAN class=""&gt;\&lt;/SPAN&gt;",&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;23\&lt;/SPAN&gt;"&lt;SPAN class=""&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;"}&lt;SPAN class=""&gt;\&lt;/SPAN&gt;"}} ", "&lt;SPAN class=""&gt;process&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;32633&lt;/SPAN&gt;, "&lt;SPAN class=""&gt;processName&lt;/SPAN&gt;"&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&amp;nbsp;"&lt;SPAN class=""&gt;MainProcess&lt;/SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to extract the file names like&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;A target="_blank" rel="noopener noreferrer"&gt;PAKS_FACT_DWH2_D20220221.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;PAKS_UBER_DWH2_D20220221.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;HHE_SIT_check_file1.txt.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;HHE_SIT_check_file2.txt.ok&lt;/A&gt;,&amp;nbsp;&lt;A target="_blank" rel="noopener noreferrer"&gt;HHE_SIT_check_file3.txt.ok &lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;separately and add them as a separate field using the below query&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;index= app_events_dwh2_de_int | rex max_match=0 "\\\\\\\\\\\\\"files\\\\\\\\\\\\\":\s*\\\\\\\\\\\\\"(?&amp;lt;File_Arrived&amp;gt;[^\\\]+)"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;but this doesn't worked. Please help us on this issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 12:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646965#M223932</guid>
      <dc:creator>Renunaren</dc:creator>
      <dc:date>2023-06-14T12:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extraction of multiple file names from an event and add it as a separate field using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646971#M223934</link>
      <description>&lt;P&gt;By not putting your event in a code block &amp;lt;/&amp;gt; as requested it gets corrupted&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ITWhisperer_0-1686746848325.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25827i18217EFCD2C9F3F6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ITWhisperer_0-1686746848325.png" alt="ITWhisperer_0-1686746848325.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please use this button&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ITWhisperer_1-1686746905019.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25828iE2CC65F2CFEA6D1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ITWhisperer_1-1686746905019.png" alt="ITWhisperer_1-1686746905019.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;to insert your example event&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 12:48:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646971#M223934</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-14T12:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extraction of multiple file names from an event and add it as a separate field using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646977#M223938</link>
      <description>&lt;P&gt;Hi IT Whisperer,&lt;/P&gt;&lt;P&gt;Thanks for your response. Please look into the sample event below.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"timestamp": "2023-06-13T09:35:27.498033Z", "level": "INFO", "filename": "splunk_sample_csv.py", "funcName": "main", "lineno": 38, "message": "Dataframe row : {\"_c0\":{\"0\":\"{\",\"1\":\" \\\"Timestamp\\\": \\\"2023\\/06\\/13 11:22:45\\\"\",\"2\":\" \\\"status\\\": \\\"files arrived\\\"\",\"3\":\" \\\"files\\\": [\",\"4\":\" \\\"PAKS_FACT_DWH2_D20220221.ok\\\"\",\"5\":\" \\\"PAKS_UBER_DWH2_D20220221.ok\\\"\",\"6\":\" \\\"HHE_SIT_check_file1.txt.ok\\\"\",\"7\":\" \\\"HHE_SIT_check_file2.txt.ok\\\"\",\"8\":\" \\\"HHE_SIT_check_file3.txt.ok\\\"\",\"9\":\" \\\"PAKS_FACT_DWH2_D20220412.ok\\\"\",\"10\":\" \\\"PAKS_FACT_DWH2_D20220420.ok\\\"\",\"11\":\" \\\"PAKS_FACT_DWH2_D20211223.ok\\\"\",\"12\":\" \\\"PAKS_FACT_DWH2_D20211224.ok\\\"\",\"13\":\" \\\"PAKS_FACT_DWH2_D20211225.ok\\\"\",\"14\":\" \\\"NOSPKP2P_DLY_NOK_D230708.ok\\\"\",\"15\":\" \\\"DUMMY_DLY_NOK_D230613.ok\\\"\",\"16\":\" \\\"DUMMY_TEST_DLY_NOK_D230613.ok\\\"\",\"17\":\" \\\"TLX2DB.PROVD.DREAM_12.ok\\\"\",\"18\":\" \\\"TLX2DB.PROVD.DREAM_152.ok\\\"\",\"19\":\" \\\"TLX2DB.PROVD.DREAM_2023-04-19-04.04.32.679000.csv.ok\\\"\",\"20\":\" \\\"TLX2DB.PROVD.DREAM_2023-04-20-05.09.39.679000.csv.ok\\\"\",\"21\":\" \\\"TLX2DB.PROVD.DREAM_2023-04-18-05.09.39.679000.csv.ok\\\"\",\"22\":\" ]\",\"23\":\"}\"}} ", "process": 32633, "processName": "MainProcess"}
&lt;/LI-CODE&gt;&lt;P&gt;Please look into the above code and kindly help us in extracting the file names like mentioned above using rex command.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 13:01:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646977#M223938</guid>
      <dc:creator>Renunaren</dc:creator>
      <dc:date>2023-06-14T13:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extraction of multiple file names from an event and add it as a separate field using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646982#M223941</link>
      <description>&lt;P&gt;First extract the list, then each file&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?:\"files[\\\\]+\": \[)(?&amp;lt;fileslist&amp;gt;[^\s:]+[^\]]+)"
| rex field=fileslist max_match=0 "(?:[^\s:]+[^\s]+\s[\"\\\]+)(?&amp;lt;files&amp;gt;[^\\\]+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 14 Jun 2023 14:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-extract-multiple-file-names-from-an-event-and-add-it/m-p/646982#M223941</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-14T14:14:14Z</dc:date>
    </item>
  </channel>
</rss>

