<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rex field extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/649793#M224663</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; How to extract&amp;nbsp;RequestID,http.endpoint,message,RequestType from these below mentioned different types logs&lt;/P&gt;&lt;P&gt;{"@version":"1","tags":["_dateparsefailure"],"host":"wh-45sg.svr.us.xyz.net","s_sourcetype":"godn","log":"{\"timestamp\":\"2023-06-21T07:45:54.528Z\",\"logger\":\"com.csa.fsces.service.3Service\",&lt;BR /&gt;\"instanceId\":\"unw-sthrage-service-green-58694cdbb8-smbjj\",\"namespace\":\"4248-ct-xrw-gkp-dev\",&lt;BR /&gt;\"platform\":\"GKP\\",\"message\":\"Entity name: NDAN_POSITION_VUE,Record type: NR, Request Id: 100185, Infdund context: 485640257604\",&lt;BR /&gt;\"level\":\"INFO\",\"traceId\":\"6492aa2326285332f853f16e2a49fd50\",&lt;BR /&gt;\"spanId\":\"9dc079cc5ef24811\",\"remote-host\":\"123.456.125.09\",&lt;BR /&gt;\"protocol\":\"HTTP/1.1\",\"http.endpoint\":\"POST /storage/e3/createfile/\",&lt;BR /&gt;\"RequestID\":\"143185\",\"user-agent\":\"Java/17.0.7\",\"RequestType\":\"TR\"}",&lt;BR /&gt;"Kubernetes.node":"hh-10feb4b660.svr.us.sj.net","appId":"5352","hostname":"gg-10geb4b660.svr.us.sj.net"}&lt;/P&gt;&lt;P&gt;{"host":"xx-1345a0196e.svr.am.abcde.net","app_id":"4324","source":"fstatabd","@version":"1",&lt;BR /&gt;"log":"{"timestamp":"2023-06-20T15:58:20.505Z","logger":"com.abcde.abcservices.service.ghstreamService",&lt;BR /&gt;"instanceId":"abc-atments-service-green-55dbdb5859-75vkl","namespace":"80458d64606-ct-abc-gkp-test",&lt;BR /&gt;"platform":"GKP","message":"Received xyz Callback Response for RequestId: 1436, Status code : 200 OK,&lt;BR /&gt;Response Payload : Successfully received the response","level":"INFO","traceId":"6491cc9c8bb8f102fafe7b07de24a457",&lt;BR /&gt;"spanId":"fafe7b07de24a457","remote-host":"123.027.16.57","protocol":"HTTP/1.1",&lt;BR /&gt;"http.endpoint":"GET /ament/p2CallBack","requestType":"RRR","requestId":"1436"}",&lt;BR /&gt;"s_sourcetype":"rost","tags":["_dateparsefailure"],&lt;BR /&gt;"Kubernetes.node":"xx-1535a0196e.svr.am.abcde.net","appId":"4324","@timestamp":"2023-06-20T15:58:31.263Z"}&lt;/P&gt;&lt;P&gt;{"log":"{\\"timestamp\\":\\"2023-06-21T07:45:54.528Z\\",\\"logger\\":\\"com.csa.fsces.service.3Service\\",&lt;BR /&gt;\\"instanceId\\":\\"unw-sthrage-service-green-58694cdbb8-smbjj\\",\\"namespace\\":\\"4248-ct-xrw-gkp-dev\\",&lt;BR /&gt;\\"platform\\":\\"GKP\\",\\"message\\":\\"Entity name: NDAN_POSITION_VUE,&lt;BR /&gt;Record type: NR, Request Id: 100185, Infdund context: 485640257604\\",&lt;BR /&gt;\\"level\\":\\"INFO\\",\\"traceId\\":\\"6492aa2326285332f853f16e2a49fd50\\",&lt;BR /&gt;\\"spanId\\":\\"9dc079cc5ef24811\\",\\"remote-host\\":\\"123.456.125.09\\",&lt;BR /&gt;\\"protocol\\":\\"HTTP/1.1\\",\\"http.endpoint\\":\\"POST /storage/e3/createfile/\\",&lt;BR /&gt;\\"RequestID\\":\\"143185\\",\\"user-agent\\":\\"Java/17.0.7\\",\\"RequestType\\":\\"TR\\"}",&lt;BR /&gt;"Kubernetes.node":"hh-10feb4b660.svr.us.sj.net","appId":"5352","hostname":"gg-10geb4b660.svr.us.sj.net"}&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jul 2023 07:54:37 GMT</pubDate>
    <dc:creator>Sangamesh</dc:creator>
    <dc:date>2023-07-10T07:54:37Z</dc:date>
    <item>
      <title>How to extract the request type and instanceId fields values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647444#M224081</link>
      <description>&lt;P&gt;{"log":"{\\"instanceId\\":\\"abc-fdh-48f-4432\\",\\"requestType\\":\\"ABC\\"}&lt;/P&gt;
&lt;P&gt;Using the above sample log, how to extract the request type and instanceId fields values?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 02:45:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647444#M224081</guid>
      <dc:creator>Sangamesh</dc:creator>
      <dc:date>2023-06-20T02:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647452#M224086</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257877"&gt;@Sangamesh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this regex&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;requestType\\\\\":\\\\\"(?&amp;lt;requestType&amp;gt;\w+)&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/WUjcyz/1" target="_blank"&gt;https://regex101.com/r/WUjcyz/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 06:52:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647452#M224086</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-19T06:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647454#M224087</link>
      <description>&lt;LI-CODE lang="markup"&gt;| foreach instanceId requestType
    [| rex "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;[^\"]+\"[^\"]+\"(?&amp;lt;&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;&amp;gt;[^\\\]+)"]&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 19 Jun 2023 06:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647454#M224087</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-19T06:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647457#M224089</link>
      <description>&lt;P&gt;This is part of a JSON object. &amp;nbsp;If the raw event is also JSON, you should have a field named "log". &amp;nbsp; Is this correct?&lt;/P&gt;&lt;P&gt;You don't need rex to extract requestType. &amp;nbsp;The best way to extract structured data is spath&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath input=log&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your sample data should give you&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;instanceId&lt;/TD&gt;&lt;TD&gt;log&lt;/TD&gt;&lt;TD&gt;requestType&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;abc-fdh-48f-4432&lt;/TD&gt;&lt;TD&gt;{"instanceId":"abc-fdh-48f-4432","requestType":"ABC"}&lt;/TD&gt;&lt;TD&gt;ABC&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If for some reason log is not available as a field, you should extract the full JSON object that contains "log" as a key, extract that JSON with spath, then extract fields contained in log using spath.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 07:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647457#M224089</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-06-19T07:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647460#M224091</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; Could you please provide brief explanation about this regex&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 07:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647460#M224091</guid>
      <dc:creator>Sangamesh</dc:creator>
      <dc:date>2023-06-19T07:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647461#M224092</link>
      <description>&lt;P&gt;&lt;SPAN&gt;log is not available as a field. Solution didn't work&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 07:37:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647461#M224092</guid>
      <dc:creator>Sangamesh</dc:creator>
      <dc:date>2023-06-19T07:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647464#M224094</link>
      <description>&lt;P&gt;The regex matches to the anchor, skips over the double quotes to get to the field contents and extracts the contents up to the next backslash (which is delimiting the contents in your example).&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 07:44:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647464#M224094</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-19T07:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647550#M224128</link>
      <description>&lt;P&gt;Can you share some raw data (anonymize as needed)? &amp;nbsp;Clearly "log" is one node in a larger JSON object. &amp;nbsp;You should try to reach that object and work down the structure rather than trying to treat structured data as string.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 07:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647550#M224128</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-06-20T07:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647555#M224130</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;How many times do we have to ask for sample data? I may consider boycotting questions without suitable data&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 08:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647555#M224130</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-20T08:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647765#M224179</link>
      <description>&lt;P&gt;Here is the sample _raw from the splunk but it has 2 different format log 1 format without double backslash(\\) and other one with double backslash(\\).How do I extract requestId,requestType,message,endpoint ?&lt;/P&gt;&lt;P&gt;{"host":"xx-1345a0196e.svr.am.abcde.net","app_id":"4324","source":"fstatabd","@version":"1",&lt;BR /&gt;"log":"{"timestamp":"2023-06-20T15:58:20.505Z","logger":"com.abcde.abcservices.service.ghstreamService",&lt;BR /&gt;"instanceId":"abc-atments-service-green-55dbdb5859-75vkl","namespace":"80458d64606-ct-abc-gkp-test",&lt;BR /&gt;"platform":"GKP","message":"Received xyz Callback Response for RequestId: 1436, Status code : 200 OK,&lt;BR /&gt;Response Payload : Successfully received the response","level":"INFO","traceId":"6491cc9c8bb8f102fafe7b07de24a457",&lt;BR /&gt;"spanId":"fafe7b07de24a457","remote-host":"123.027.16.57","protocol":"HTTP/1.1",&lt;BR /&gt;"http.endpoint":"GET /ament/p2CallBack","requestType":"RRR","requestId":"1436"}",&lt;BR /&gt;"s_sourcetype":"rost","tags":["_dateparsefailure"],&lt;BR /&gt;"Kubernetes.node":"xx-1535a0196e.svr.am.abcde.net","appId":"4324","@timestamp":"2023-06-20T15:58:31.263Z"}&lt;/P&gt;&lt;P&gt;{"log":"{\\"timestamp\\":\\"2023-06-21T07:45:54.528Z\\",\\"logger\\":\\"com.csa.fsces.service.3Service\\",&lt;BR /&gt;\\"instanceId\\":\\"unw-sthrage-service-green-58694cdbb8-smbjj\\",\\"namespace\\":\\"4248-ct-xrw-gkp-dev\\",&lt;BR /&gt;\\"platform\\":\\"GKP\\",\\"message\\":\\"Entity name: NDAN_POSITION_VUE,&lt;BR /&gt;Record type: NR, Request Id: 100185, Infdund context: 485640257604\\",&lt;BR /&gt;\\"level\\":\\"INFO\\",\\"traceId\\":\\"6492aa2326285332f853f16e2a49fd50\\",&lt;BR /&gt;\\"spanId\\":\\"9dc079cc5ef24811\\",\\"remote-host\\":\\"123.456.125.09\\",&lt;BR /&gt;\\"protocol\\":\\"HTTP/1.1\\",\\"http.endpoint\\":\\"POST /storage/e3/createfile/\\",&lt;BR /&gt;\\"RequestID\\":\\"143185\\",\\"user-agent\\":\\"Java/17.0.7\\",\\"RequestType\\":\\"TR\\"}",&lt;BR /&gt;"Kubernetes.node":"hh-10feb4b660.svr.us.sj.net","appId":"5352","hostname":"gg-10geb4b660.svr.us.sj.net"}&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 11:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647765#M224179</guid>
      <dc:creator>Sangamesh</dc:creator>
      <dc:date>2023-06-21T11:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647771#M224181</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "\"(requestId|RequestID\\\+)\":[^\"]*\"(?&amp;lt;requestId&amp;gt;[^\"\\\]+)"
| rex "\"(requestType|RequestType\\\+)\":[^\"]*\"(?&amp;lt;requestType&amp;gt;[^\"\\\]+)"
| rex "\"(message|message\\\+)\":[^\"]*\"(?&amp;lt;message&amp;gt;[^\"\\\]+)"
| rex "\"(http\.endpoint|http\.endpoint\\\+)\":[^\"]*\"(?&amp;lt;httpEndpoint&amp;gt;[^\"\\\]+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 21 Jun 2023 12:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647771#M224181</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-21T12:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647775#M224182</link>
      <description>&lt;P&gt;Please provide the steps for creation of dynamic dashboard with using the previous solution output.It should include timestamp ,requestId,instanceId,message ,endpoint.&lt;/P&gt;&lt;P&gt;requestid,requesttype should be the dropdown menu and Date should be the calendar text field .based on these combination selections ,it should be populate the data in dashboard&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 12:34:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647775#M224182</guid>
      <dc:creator>Sangamesh</dc:creator>
      <dc:date>2023-06-21T12:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647784#M224185</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257877"&gt;@Sangamesh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 13:11:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/647784#M224185</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-21T13:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/649793#M224663</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; How to extract&amp;nbsp;RequestID,http.endpoint,message,RequestType from these below mentioned different types logs&lt;/P&gt;&lt;P&gt;{"@version":"1","tags":["_dateparsefailure"],"host":"wh-45sg.svr.us.xyz.net","s_sourcetype":"godn","log":"{\"timestamp\":\"2023-06-21T07:45:54.528Z\",\"logger\":\"com.csa.fsces.service.3Service\",&lt;BR /&gt;\"instanceId\":\"unw-sthrage-service-green-58694cdbb8-smbjj\",\"namespace\":\"4248-ct-xrw-gkp-dev\",&lt;BR /&gt;\"platform\":\"GKP\\",\"message\":\"Entity name: NDAN_POSITION_VUE,Record type: NR, Request Id: 100185, Infdund context: 485640257604\",&lt;BR /&gt;\"level\":\"INFO\",\"traceId\":\"6492aa2326285332f853f16e2a49fd50\",&lt;BR /&gt;\"spanId\":\"9dc079cc5ef24811\",\"remote-host\":\"123.456.125.09\",&lt;BR /&gt;\"protocol\":\"HTTP/1.1\",\"http.endpoint\":\"POST /storage/e3/createfile/\",&lt;BR /&gt;\"RequestID\":\"143185\",\"user-agent\":\"Java/17.0.7\",\"RequestType\":\"TR\"}",&lt;BR /&gt;"Kubernetes.node":"hh-10feb4b660.svr.us.sj.net","appId":"5352","hostname":"gg-10geb4b660.svr.us.sj.net"}&lt;/P&gt;&lt;P&gt;{"host":"xx-1345a0196e.svr.am.abcde.net","app_id":"4324","source":"fstatabd","@version":"1",&lt;BR /&gt;"log":"{"timestamp":"2023-06-20T15:58:20.505Z","logger":"com.abcde.abcservices.service.ghstreamService",&lt;BR /&gt;"instanceId":"abc-atments-service-green-55dbdb5859-75vkl","namespace":"80458d64606-ct-abc-gkp-test",&lt;BR /&gt;"platform":"GKP","message":"Received xyz Callback Response for RequestId: 1436, Status code : 200 OK,&lt;BR /&gt;Response Payload : Successfully received the response","level":"INFO","traceId":"6491cc9c8bb8f102fafe7b07de24a457",&lt;BR /&gt;"spanId":"fafe7b07de24a457","remote-host":"123.027.16.57","protocol":"HTTP/1.1",&lt;BR /&gt;"http.endpoint":"GET /ament/p2CallBack","requestType":"RRR","requestId":"1436"}",&lt;BR /&gt;"s_sourcetype":"rost","tags":["_dateparsefailure"],&lt;BR /&gt;"Kubernetes.node":"xx-1535a0196e.svr.am.abcde.net","appId":"4324","@timestamp":"2023-06-20T15:58:31.263Z"}&lt;/P&gt;&lt;P&gt;{"log":"{\\"timestamp\\":\\"2023-06-21T07:45:54.528Z\\",\\"logger\\":\\"com.csa.fsces.service.3Service\\",&lt;BR /&gt;\\"instanceId\\":\\"unw-sthrage-service-green-58694cdbb8-smbjj\\",\\"namespace\\":\\"4248-ct-xrw-gkp-dev\\",&lt;BR /&gt;\\"platform\\":\\"GKP\\",\\"message\\":\\"Entity name: NDAN_POSITION_VUE,&lt;BR /&gt;Record type: NR, Request Id: 100185, Infdund context: 485640257604\\",&lt;BR /&gt;\\"level\\":\\"INFO\\",\\"traceId\\":\\"6492aa2326285332f853f16e2a49fd50\\",&lt;BR /&gt;\\"spanId\\":\\"9dc079cc5ef24811\\",\\"remote-host\\":\\"123.456.125.09\\",&lt;BR /&gt;\\"protocol\\":\\"HTTP/1.1\\",\\"http.endpoint\\":\\"POST /storage/e3/createfile/\\",&lt;BR /&gt;\\"RequestID\\":\\"143185\\",\\"user-agent\\":\\"Java/17.0.7\\",\\"RequestType\\":\\"TR\\"}",&lt;BR /&gt;"Kubernetes.node":"hh-10feb4b660.svr.us.sj.net","appId":"5352","hostname":"gg-10geb4b660.svr.us.sj.net"}&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 07:54:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/649793#M224663</guid>
      <dc:creator>Sangamesh</dc:creator>
      <dc:date>2023-07-10T07:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/649803#M224667</link>
      <description>&lt;P&gt;Use the solution previously accepted.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 08:34:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/649803#M224667</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-10T08:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rex field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/649924#M224700</link>
      <description>&lt;P&gt;Again, if your developer has done their homework, they would have written conformant JSON, meaning that you can have more robust field extraction using simpler commands, like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath input=log ``` 1st format should have log.requestType as a field
  2nd format's log field is a string containing escaped JSON containing a node RequestType ```
| eval RequestType = coalesce(RequestType, 'log.requestType')&lt;/LI-CODE&gt;&lt;P&gt;There are some strange errors in the samples you cited. &amp;nbsp;If they are actual errors, you should ask your developer to fix them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 06:34:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-the-request-type-and-instanceId-fields-values/m-p/649924#M224700</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-07-11T06:34:49Z</dc:date>
    </item>
  </channel>
</rss>

