<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract message from log events. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651100#M225119</link>
    <description>&lt;P&gt;I have tried the above query but from that I am getting the whole message I only want to extract the 1 and 2 line .&lt;BR /&gt;I have tried this and getting only until successful in the table I want the whole line&amp;nbsp;&lt;SPAN&gt;'until-successful' retries exhausted&lt;/SPAN&gt;&lt;BR /&gt;| rex field=message "(?ms)Message\s+'(?&amp;lt;message&amp;gt;.*?)'"&lt;BR /&gt;| table message&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 09:35:15 GMT</pubDate>
    <dc:creator>avi7326</dc:creator>
    <dc:date>2023-07-19T09:35:15Z</dc:date>
    <item>
      <title>How to extract message from log events.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651098#M225117</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;I want to extract the message that is&amp;nbsp;&lt;SPAN class=""&gt;'until-successful' retries exhausted from the below logs.&lt;BR /&gt;And also a second rex query to extract both message and element and get in the table.&lt;BR /&gt;Any Help will be appreciated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;{&amp;nbsp;&lt;/SPAN&gt;&lt;A title="Original URL: https://splunkeu.bmwgroup.net/en-US/app/search/search?earliest=-24h%40h&amp;amp;latest=now&amp;amp;q=search%20index%3Dus_whcrm%20%20sourcetype%3D%22bmw-sl-nsp-prd-api%22%20source%3DMuleUSAppLogs%20logger%3Dorg.mule.runtime.core.internal.exception.OnErrorPropagateHandler%0A%7Cdedup%20properties.correlationId&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1689756449.354722_A1AACC25-F417-4F61-B253-89557D014363. Click or tap if you trust this link." href="https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsplunkeu.bmwgroup.net%2Fen-US%2Fapp%2Fsearch%2Fsearch%3Fearliest%3D-24h%2540h%26latest%3Dnow%26q%3Dsearch%2520index%253Dus_whcrm%2520%2520sourcetype%253D%2522bmw-sl-nsp-prd-api%2522%2520source%253DMuleUSAppLogs%2520logger%253Dorg.mule.runtime.core.internal.exception.OnErrorPropagateHandler%250A%257Cdedup%2520properties.correlationId%26display.page.search.mode%3Dsmart%26dispatch.sample_ratio%3D1%26display.page.search.tab%3Devents%26display.general.type%3Devents%26sid%3D1689756449.354722_A1AACC25-F417-4F61-B253-89557D014363&amp;amp;data=05%7C01%7CAwarshika.Kushwaha%40cognizant.com%7Cc3cdb1fa33b7453da5c908db88362c81%7Cde08c40719b9427d9fe8edf254300ca7%7C0%7C0%7C638253538486990859%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;amp;sdata=Fh%2FySSBEOljKCxA54f5s7i%2FXQK8zEhMC%2Ba3h4%2BZ6nMU%3D&amp;amp;reserved=0" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;[-]&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;logger&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;org.mule.runtime.core.internal.exception.OnErrorPropagateHandler&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;message&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;********************************************************************************&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Message &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: 'until-successful' retries exhausted&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;Element &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: bmw-sl-nsp-case-readSub_Flow/processors/1 @ bmw-sl-nsp-prd-api:write/bmw-sl-nsp-case-read.xml:88 (Until Successful)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Element DSL &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: &amp;lt;until-successful maxRetries="${max.retries}" doc:name="Until Successful" doc:id="b76dd101-8752-43aa-ab94-d548b699ea7a" millisBetweenRetries="${time.between.retires.case}"&amp;gt; &amp;lt;http:request method="GET" doc:name="Get Cases" doc:id="b846734d-4ff0-479d-bc21-e112cd9e8919" config-ref="HTTP_Request_configuration" path="${schedular.getcases.target.path}" sendCorrelationId="ALWAYS" correlationId="#[correlationId]"&amp;gt; &amp;lt;http:query-params&amp;gt;&amp;lt;![CDATA[ #[output application/java --- { "startTimestamp" : vars.startTimestamp, "country" : vars.currentCountry, "endTimestamp" : vars.endTimestamp, "businessUnit" : vars.currentBusinessUnit }]&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 09:00:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651098#M225117</guid>
      <dc:creator>avi7326</dc:creator>
      <dc:date>2023-07-19T09:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract message from log events.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651099#M225118</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246450"&gt;@avi7326&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this seems to be a json log, so you can use "INDEXED_EXTRACTIONS =json" at the ingestion or the "spath" command during the search.&lt;/P&gt;&lt;P&gt;Anyway, you can extract this string also using a regex like the following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "Message\s+:\s+(?&amp;lt;message&amp;gt;.+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/OhTHyC/1" target="_blank"&gt;https://regex101.com/r/OhTHyC/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 09:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651099#M225118</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-19T09:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract message from log events.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651100#M225119</link>
      <description>&lt;P&gt;I have tried the above query but from that I am getting the whole message I only want to extract the 1 and 2 line .&lt;BR /&gt;I have tried this and getting only until successful in the table I want the whole line&amp;nbsp;&lt;SPAN&gt;'until-successful' retries exhausted&lt;/SPAN&gt;&lt;BR /&gt;| rex field=message "(?ms)Message\s+'(?&amp;lt;message&amp;gt;.*?)'"&lt;BR /&gt;| table message&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 09:35:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651100#M225119</guid>
      <dc:creator>avi7326</dc:creator>
      <dc:date>2023-07-19T09:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract message from log events.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651101#M225120</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have tried the above query but from that I am getting the whole message I only want to extract the 1 and 2 line .&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have tried this and getting only until successful in the table I want the whole line&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'until-successful' retries exhausted&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| rex field=message "(?ms)Message\s+'(?&amp;lt;message&amp;gt;.*?)'"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| table message&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 09:56:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651101#M225120</guid>
      <dc:creator>avi7326</dc:creator>
      <dc:date>2023-07-19T09:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract message from log events.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651120#M225132</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246450"&gt;@avi7326&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: you want to extract only the logger and message rows in two different fields, is it correct?&lt;/P&gt;&lt;P&gt;in this case, please try this regex&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?ms)logger:(?&amp;lt;logger&amp;gt;.*)\s*message:\s+(?&amp;lt;message&amp;gt;.*)Message"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/OhTHyC/2" target="_blank"&gt;https://regex101.com/r/OhTHyC/2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 13:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-message-from-log-events/m-p/651120#M225132</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-19T13:04:23Z</dc:date>
    </item>
  </channel>
</rss>

