<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661301#M228313</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254877"&gt;@bmanikya&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;does my regex work?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2023 06:31:38 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-10-19T06:31:38Z</dc:date>
    <item>
      <title>Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661003#M228212</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmanikya_1-1697543560778.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27611iDCF92807DE3F4796/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bmanikya_1-1697543560778.png" alt="bmanikya_1-1697543560778.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmanikya_2-1697543592146.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27612i2174EBA8A4D184FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bmanikya_2-1697543592146.png" alt="bmanikya_2-1697543592146.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Above is the event, not sure why this is showing up as two different events. Anyways, I have written a splunk query according to my requirements but output is not good.&amp;nbsp; I want to get rid of Service and Maintenance Start time in MST.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bmanikya_0-1697543531428.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27610iE392D2A26762A804/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bmanikya_0-1697543531428.png" alt="bmanikya_0-1697543531428.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 11:56:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661003#M228212</guid>
      <dc:creator>bmanikya</dc:creator>
      <dc:date>2023-10-17T11:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661006#M228215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254877"&gt;@bmanikya&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to help you in a regex extraction, you should share your events in text mode (eventually using the Insert/Edit Code Sample button), highlighting the parts to extract.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 12:04:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661006#M228215</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-17T12:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661168#M228272</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;MIME-Version:&lt;/SPAN&gt; &lt;SPAN class=""&gt;1.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Content-Disposition:&lt;/SPAN&gt; &lt;SPAN class=""&gt;inline&lt;/SPAN&gt; &lt;SPAN class=""&gt;Subject:&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;Services&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;over&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;hours&lt;/SPAN&gt; -- &lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class=""&gt;Content-Type:&lt;/SPAN&gt; &lt;SPAN class=""&gt;text/html&lt;/SPAN&gt; &amp;lt;&lt;SPAN class=""&gt;font&lt;/SPAN&gt; &lt;SPAN class=""&gt;size=3&lt;/SPAN&gt; &lt;SPAN class=""&gt;color=black&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Hi&lt;/SPAN&gt; &lt;SPAN class=""&gt;Team&lt;/SPAN&gt;,&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Please&lt;/SPAN&gt; &lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;SPAN class=""&gt;below&lt;/SPAN&gt; &lt;SPAN class=""&gt;servers&lt;/SPAN&gt; &lt;SPAN class=""&gt;which&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;more&lt;/SPAN&gt; &lt;SPAN class=""&gt;than&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;hours&lt;/SPAN&gt;; &amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/font&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;table&lt;/SPAN&gt; &lt;SPAN class=""&gt;border=2&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=2&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Cluster&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name:&lt;/SPAN&gt; &lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/TR&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&amp;gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Service&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&amp;gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Start&lt;/SPAN&gt; &lt;SPAN class=""&gt;Time&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;MST&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/TR&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#FFB6C1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;oozie&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Mon&lt;/SPAN&gt; &lt;SPAN class=""&gt;Oct&lt;/SPAN&gt; &lt;SPAN class=""&gt;16&lt;/SPAN&gt; &lt;SPAN class=""&gt;07:29:46&lt;/SPAN&gt; &lt;SPAN class=""&gt;MST&lt;/SPAN&gt; &lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/table&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;font&lt;/SPAN&gt; &lt;SPAN class=""&gt;size=3&lt;/SPAN&gt; &lt;SPAN class=""&gt;color=black&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Script&lt;/SPAN&gt; &lt;SPAN class=""&gt;Path:/amex/ansible/maintenance_mode_service&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/font&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;font&lt;/SPAN&gt; &lt;SPAN class=""&gt;size=3&lt;/SPAN&gt; &lt;SPAN class=""&gt;color=black&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Thank&lt;/SPAN&gt; &lt;SPAN class=""&gt;you&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;BDP&lt;/SPAN&gt; &lt;SPAN class=""&gt;Spark&lt;/SPAN&gt; &lt;SPAN class=""&gt;Support&lt;/SPAN&gt; &lt;SPAN class=""&gt;Team&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/font&amp;gt;&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Need field extractions of the following.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Cluster Name: AtWork-CIW-E1&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Service&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Maintenance Start Time in MST&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;oozie&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Mon Oct 16 07:29:46 MST 2023&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 18 Oct 2023 10:04:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661168#M228272</guid>
      <dc:creator>bmanikya</dc:creator>
      <dc:date>2023-10-18T10:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661170#M228273</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254877"&gt;@bmanikya&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;using your one sample, I can propose to yu this regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?ms)\s-\s(?&amp;lt;Service&amp;gt;[^-]*).*oozie(\&amp;lt;[^\&amp;gt;]*\&amp;gt;){2}(?&amp;lt;oozie&amp;gt;[^\&amp;lt;]*)&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/tzacfN/1" target="_blank"&gt;https://regex101.com/r/tzacfN/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you could share more samples (always in text mode) I could verify the above regex.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 10:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661170#M228273</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-18T10:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661173#M228274</link>
      <description>&lt;P&gt;Here is my Splunk query,&amp;nbsp; Output is not good&lt;/P&gt;&lt;P&gt;rex max_match=0 ^\w+:\s+\w+\.\w+@\w+\.\w+\s+\w+:\s+\w+\-\w+\-\w+@\w+\.\w+\s+\w+\-\w+:\s+\d+\.\d+\s+\w+\-\w+:\s+\w+\s+\w+:\s+\w+\s+\-\s+(?P&amp;lt;Info&amp;gt;\w+\s+\w+\s+\w+\s+\w+\s+\w+\s+\w+\s+\d+\s+\w+)\s+\-\-\s+(?P&amp;lt;ClusterName&amp;gt;\w+\-\w+\-\w+) |rex "(?ms)^(?:[^&amp;gt;\\n]*&amp;gt;){2}(?P&amp;lt;Svc&amp;gt;\\w+)[^=\\n]*=\\d+&amp;gt;(?P&amp;lt;Maint&amp;gt;[^&amp;lt;]+)" | table Info ClusterName Svc Maint&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Info ClusterName Svc Maint&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Services are in Maintenance Mode over 2 hours&lt;/TD&gt;&lt;TD&gt;AtWork-CIW-E1&lt;/TD&gt;&lt;TD&gt;Service&lt;/TD&gt;&lt;TD&gt;Maintenance Start Time in MST&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;oozie&lt;/TD&gt;&lt;TD&gt;Mon Oct 16 07:29:46 MST 2023&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the above output, it is capturing Service and Maintenance Start time in MST in the field extractions&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 10:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661173#M228274</guid>
      <dc:creator>bmanikya</dc:creator>
      <dc:date>2023-10-18T10:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661301#M228313</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254877"&gt;@bmanikya&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;does my regex work?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 06:31:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661301#M228313</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-19T06:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661348#M228325</link>
      <description>&lt;P&gt;No&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 10:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661348#M228325</guid>
      <dc:creator>bmanikya</dc:creator>
      <dc:date>2023-10-19T10:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661355#M228331</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254877"&gt;@bmanikya&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you share more sample logs?&lt;/P&gt;&lt;P&gt;because, as you can see in regex101.com, my regex works on the shared sample.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661355#M228331</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-19T11:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661356#M228332</link>
      <description>&lt;P&gt;I have already shared before, events are in HTML.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Disposition:&lt;/SPAN&gt; &lt;SPAN class=""&gt;inline&lt;/SPAN&gt; &lt;SPAN class=""&gt;Subject:&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;Services&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;over&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;hours&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; -- &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class=""&gt;Content-Type:&lt;/SPAN&gt; &lt;SPAN class=""&gt;text/html&lt;/SPAN&gt;&lt;SPAN&gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;font&lt;/SPAN&gt; &lt;SPAN class=""&gt;size=3&lt;/SPAN&gt; &lt;SPAN class=""&gt;color=black&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Hi&lt;/SPAN&gt; &lt;SPAN class=""&gt;Team&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Please&lt;/SPAN&gt; &lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;SPAN class=""&gt;below&lt;/SPAN&gt; &lt;SPAN class=""&gt;servers&lt;/SPAN&gt; &lt;SPAN class=""&gt;which&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;more&lt;/SPAN&gt; &lt;SPAN class=""&gt;than&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;hours&lt;/SPAN&gt;&lt;SPAN&gt;; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/font&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;table&lt;/SPAN&gt; &lt;SPAN class=""&gt;border=2&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=2&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cluster&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name:&lt;/SPAN&gt; &lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Service&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Start&lt;/SPAN&gt; &lt;SPAN class=""&gt;Time&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;MST&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TR&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#FFB6C1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;oozie&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Mon&lt;/SPAN&gt; &lt;SPAN class=""&gt;Oct&lt;/SPAN&gt; &lt;SPAN class=""&gt;16&lt;/SPAN&gt; &lt;SPAN class=""&gt;07:29:46&lt;/SPAN&gt; &lt;SPAN class=""&gt;MST&lt;/SPAN&gt; &lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/TR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/table&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;font&lt;/SPAN&gt; &lt;SPAN class=""&gt;size=3&lt;/SPAN&gt; &lt;SPAN class=""&gt;color=black&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please check in Bold characters. I want this in table format&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:53:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/661356#M228332</guid>
      <dc:creator>bmanikya</dc:creator>
      <dc:date>2023-10-19T11:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/665155#M228357</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;Above is the event, not sure why this is showing up as two different events. Anyways, I have written a splunk query according to my requirements but output is not good.&amp;nbsp; I want to get rid of Service and Maintenance Start time in MST.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Let me summarize the use case: You have ONE single log,&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Mon Oct 16 07:29:46 MST 2023&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;MIME-Version:&lt;/SPAN&gt; &lt;SPAN class=""&gt;1.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Content-Disposition:&lt;/SPAN&gt; &lt;SPAN class=""&gt;inline&lt;/SPAN&gt; &lt;SPAN class=""&gt;Subject:&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;Services&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;over&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;SPAN class=""&gt;hours&lt;/SPAN&gt; -- &lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class=""&gt;Content-Type:&lt;/SPAN&gt; &lt;SPAN class=""&gt;text/html&lt;/SPAN&gt; &amp;lt;&lt;SPAN class=""&gt;font&lt;/SPAN&gt; &lt;SPAN class=""&gt;size=3&lt;/SPAN&gt; &lt;SPAN class=""&gt;color=black&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Hi&lt;/SPAN&gt; &lt;SPAN class=""&gt;Team&lt;/SPAN&gt;,&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Please&lt;/SPAN&gt;&lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;SPAN class=""&gt;below&lt;/SPAN&gt; &lt;SPAN class=""&gt;servers&lt;/SPAN&gt; &lt;SPAN class=""&gt;which&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;more&lt;/SPAN&gt; &lt;SPAN class=""&gt;than&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;hours&lt;/SPAN&gt;; &amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/font&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;table&lt;/SPAN&gt;&lt;SPAN class=""&gt;border=2&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=2&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Cluster&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name:&lt;/SPAN&gt; &lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/TR&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt;&lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&amp;gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Service&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&amp;gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Start&lt;/SPAN&gt; &lt;SPAN class=""&gt;Time&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt;&lt;SPAN class=""&gt;MST&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/TR&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;TR bgcolor=#FFB6C1&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;TH colspan=1&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;oozie&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/TH&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;TH colspan=1&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;Mon Oct 16 07:29:46 MST 2023&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/TH&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/TR&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;/table&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;font size=3 color=black&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;ScriptPath:/amex/ansible/maintenance_mode_service&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/font&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;font size=3 color=black&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;Thankyou&lt;SPAN&gt;,&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;BDP Spark Support Team&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/font&amp;gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;But Splunk indexer gives you TWO events (with different time values)&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Mon Oct 16 07:31:53 MST 2023&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;MIME-Version:&lt;/SPAN&gt; &lt;SPAN class=""&gt;1.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Content-Disposition:&lt;/SPAN&gt; &lt;SPAN class=""&gt;inline&lt;/SPAN&gt; &lt;SPAN class=""&gt;Subject:&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;Services&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;over&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;SPAN class=""&gt;hours&lt;/SPAN&gt; -- &lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class=""&gt;Content-Type:&lt;/SPAN&gt; &lt;SPAN class=""&gt;text/html&lt;/SPAN&gt; &amp;lt;&lt;SPAN class=""&gt;font&lt;/SPAN&gt; &lt;SPAN class=""&gt;size=3&lt;/SPAN&gt; &lt;SPAN class=""&gt;color=black&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Hi&lt;/SPAN&gt; &lt;SPAN class=""&gt;Team&lt;/SPAN&gt;,&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Please&lt;/SPAN&gt;&lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;SPAN class=""&gt;below&lt;/SPAN&gt; &lt;SPAN class=""&gt;servers&lt;/SPAN&gt; &lt;SPAN class=""&gt;which&lt;/SPAN&gt; &lt;SPAN class=""&gt;are&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;mode&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;more&lt;/SPAN&gt; &lt;SPAN class=""&gt;than&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;hours&lt;/SPAN&gt;; &amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/br&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/font&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;table&lt;/SPAN&gt;&lt;SPAN class=""&gt;border=2&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt; &lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=2&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;Cluster&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name:&lt;/SPAN&gt; &lt;SPAN class=""&gt;AtWork-CIW-E1&lt;/SPAN&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/TR&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class=""&gt;TR&lt;/SPAN&gt;&lt;SPAN class=""&gt;bgcolor=#D6EAF8&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&amp;gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Service&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;TH&lt;/SPAN&gt; &lt;SPAN class=""&gt;colspan=1&lt;/SPAN&gt;&amp;gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Maintenance&lt;/SPAN&gt; &lt;SPAN class=""&gt;Start&lt;/SPAN&gt; &lt;SPAN class=""&gt;Time&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt;&lt;SPAN class=""&gt;MST&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;lt;&lt;SPAN class=""&gt;/TH&lt;/SPAN&gt;&amp;gt;&amp;lt;&lt;SPAN class=""&gt;/TR&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Mon Oct 16 07:29:46 MST 2023&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;TR bgcolor=#FFB6C1&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;TH colspan=1&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;oozie&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/TH&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;TH colspan=1&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;Mon Oct 16 07:29:46 MST2023&lt;/STRONG&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/TH&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/TR&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;/table&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;font size=3 color=black&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;ScriptPath:/amex/ansible/maintenance_mode_service&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/font&lt;SPAN&gt;&amp;gt; &amp;lt;&lt;/SPAN&gt;font size=3 color=black&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;Thankyou&lt;SPAN&gt;,&amp;lt;&lt;/SPAN&gt;/br&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;BDP Spark Support Team&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;/font&amp;gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;You want to use search command to combine data in these two into one table row. &amp;nbsp;Is this correct?&lt;/P&gt;&lt;P&gt;Most importantly, you have a line break problem in ingestion. &amp;nbsp;This is where you &lt;STRONG&gt;really&lt;/STRONG&gt; need to fix. &amp;nbsp;By default, Splunk has the habit of hunting for timestamp and use it as a clue that a new event exists. &amp;nbsp;This is why the "second" event has the time&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN&gt;Mon Oct 16 07:29:46 MST 2023 which is actually the maintenance start time, not the time of log &lt;U&gt;which should be later&lt;/U&gt;, namely&amp;nbsp;Mon Oct 16 07:31:53 MST 2023. &amp;nbsp;If you do not fix line break problem, there is no end to troubles down the road no matter how many clever ways you can devise to work around it.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;This said, it is possible to work around this particular log by restoring the complete log using &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction" target="_blank" rel="noopener"&gt;transaction&lt;/A&gt;. (Warning: The workaround may break other things.)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Second, try not to capture everything by counting word breaks or even HTML tags. &amp;nbsp;HTML is really the worst enemy of Splunk because HTML's semantics is totally separate from semantics of content. &amp;nbsp;Always try to anchor regex on 1) content semantics, 2) HTML semantics. &amp;nbsp;Here is a proposal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transaction startswith="Script Path" endswith="MIME-Version"
| eval _time = _time + duration ``` restore actual event time; this may not be of interest ```
| rex "Cluster Name:\s*(?&amp;lt;ClusterName&amp;gt;[^&amp;lt;]+)"
| rex "&amp;lt;TR[^&amp;gt;]*&amp;gt;&amp;lt;TH[^&amp;gt;]*&amp;gt;(?&amp;lt;Service&amp;gt;[^&amp;lt;]+)&amp;lt;\/TH&amp;gt;&amp;lt;TH[^&amp;gt;]*&amp;gt;(?&amp;lt;MaintenanceStartTime&amp;gt;[^&amp;lt;]+)"
| table ClusterName Service MaintenanceStartTime&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The two events should give you&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ClusterName&lt;/TD&gt;&lt;TD&gt;Service&lt;/TD&gt;&lt;TD&gt;MaintenanceStartTime&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;AtWork-CIW-E1&lt;/TD&gt;&lt;TD&gt;oozie&lt;/TD&gt;&lt;TD&gt;Mon Oct 16 07:29:46 MST 2023&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here is the emulation that you can play with and compare with real data&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval data=split("MIME-Version: 1.0 Content-Disposition: inline Subject: INFO - Services are in Maintenance Mode over 2 hours -- AtWork-CIW-E1 Content-Type: text/html &amp;lt;font size=3 color=black&amp;gt;Hi Team,&amp;lt;/br&amp;gt;&amp;lt;/br&amp;gt;Please find below servers which are in maintenance mode for more than 2 hours; &amp;lt;/br&amp;gt;&amp;lt;/br&amp;gt;&amp;lt;/font&amp;gt; &amp;lt;table border=2&amp;gt; &amp;lt;TR bgcolor=#D6EAF8&amp;gt;&amp;lt;TH colspan=2&amp;gt;Cluster Name: AtWork-CIW-E1&amp;lt;/TH&amp;gt;&amp;lt;/TR&amp;gt; &amp;lt;TR bgcolor=#D6EAF8&amp;gt;&amp;lt;TH colspan=1&amp;gt;Service&amp;lt;/TH&amp;gt;&amp;lt;TH colspan=1&amp;gt;Maintenance Start Time in MST&amp;lt;/TH&amp;gt;&amp;lt;/TR&amp;gt;
&amp;lt;TR bgcolor=#FFB6C1&amp;gt;&amp;lt;TH colspan=1&amp;gt;oozie&amp;lt;/TH&amp;gt;&amp;lt;TH colspan=1&amp;gt;Mon Oct 16 07:29:46 MST 2023&amp;lt;/TH&amp;gt;&amp;lt;/TR&amp;gt; &amp;lt;/table&amp;gt; &amp;lt;font size=3 color=black&amp;gt;&amp;lt;/br&amp;gt; Script Path:/amex/ansible/maintenance_mode_service&amp;lt;/font&amp;gt; &amp;lt;font size=3 color=black&amp;gt;&amp;lt;/br&amp;gt;&amp;lt;/br&amp;gt;Thank you,&amp;lt;/br&amp;gt;BDP Spark Support Team&amp;lt;/font&amp;gt;", "
")
| mvexpand data
| eval _time = if(match(data, "Mon Oct 16 07:29:46 MST 2023"), strptime("Mon Oct 16 07:29:46 MST 2023", "%a %b %d %H:%M:%S %Z %Y"), strptime("Mon Oct 16 07:31:53 MST 2023", "%a %b %d %H:%M:%S %Z %Y"))
| rename data AS _raw
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do not forget: Your most important task is to fix line breaks. (There are many guides in Splunk documents, and various answers in this forum.)&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 17:14:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-regex/m-p/665155#M228357</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-10-19T17:14:23Z</dc:date>
    </item>
  </channel>
</rss>

