<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Help in extracting the field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676584#M231383</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@AL3Z&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "System\.Exception:\s+(?&amp;lt;system_exception&amp;gt;[^\(\']+)"&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 05 Feb 2024 13:28:39 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2024-02-05T13:28:39Z</dc:date>
    <item>
      <title>Need Help in extracting the field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676575#M231381</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;help me extracting the field from the below two events&lt;BR /&gt;&lt;SPAN class=""&gt;System.Exception:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Assertion&lt;/SPAN&gt; &lt;SPAN class=""&gt;violated:&lt;/SPAN&gt; &lt;SPAN class=""&gt;stream.ReadByteInto&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;bufferStream&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;==&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x03&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;System.Exception:&lt;/SPAN&gt; &lt;SPAN class=""&gt;An&lt;/SPAN&gt; &lt;SPAN class=""&gt;error&lt;/SPAN&gt; &lt;SPAN class=""&gt;was&lt;/SPAN&gt; &lt;SPAN class=""&gt;encountered&lt;/SPAN&gt; &lt;SPAN class=""&gt;while&lt;/SPAN&gt; &lt;SPAN class=""&gt;attempt&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;fetch&lt;/SPAN&gt; &lt;SPAN class=""&gt;proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;credentials&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;user 'xyz&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;system_exception=&lt;SPAN class=""&gt;Assertion&lt;/SPAN&gt; &lt;SPAN class=""&gt;violated:&lt;/SPAN&gt; &lt;SPAN class=""&gt;stream.ReadByteInto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;An&lt;/SPAN&gt; &lt;SPAN class=""&gt;error&lt;/SPAN&gt; &lt;SPAN class=""&gt;was&lt;/SPAN&gt; &lt;SPAN class=""&gt;encountered&lt;/SPAN&gt; &lt;SPAN class=""&gt;while&lt;/SPAN&gt; &lt;SPAN class=""&gt;attempt&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;fetch&lt;/SPAN&gt; &lt;SPAN class=""&gt;proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;credentials&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 12:19:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676575#M231381</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2024-02-05T12:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extracting the field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676584#M231383</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@AL3Z&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "System\.Exception:\s+(?&amp;lt;system_exception&amp;gt;[^\(\']+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 05 Feb 2024 13:28:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676584#M231383</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-02-05T13:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extracting the field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676589#M231385</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Can you pls explain this part I didnt understand&amp;nbsp; [^\(\']+)&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 14:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676589#M231385</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2024-02-05T14:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help in extracting the field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676607#M231391</link>
      <description>Hi&lt;BR /&gt;I match all other characters except ( and ' and there must be at least one or more those with any order and combination.&lt;BR /&gt;You can test these e.g. regex101.com.&lt;BR /&gt;There is also descriptions what all those anchors etc. are/meaning.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Mon, 05 Feb 2024 15:28:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-in-extracting-the-field/m-p/676607#M231391</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-02-05T15:28:37Z</dc:date>
    </item>
  </channel>
</rss>

