<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex Help to extract fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-Help-to-extract-fields/m-p/678174#M231932</link>
    <description>&lt;P&gt;Before I invest too much time working on a regex, please can you share your events in a code block &amp;lt;/&amp;gt;. Also, do your events really have "Part" in them? (Regex matches in patterns and unless the patterns are accurate, the match will not be found.)&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 11:11:52 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-02-21T11:11:52Z</dc:date>
    <item>
      <title>Regex Help to extract fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Help-to-extract-fields/m-p/678171#M231929</link>
      <description>&lt;P&gt;Can some one please help with the regex that can be used to view the below event in tabular format.&lt;/P&gt;&lt;P&gt;Event&lt;/P&gt;&lt;P&gt;INFO &amp;gt; 2024-02-02 16:12:12,222 - [application logs message]:&lt;/P&gt;&lt;P&gt;==============================================&lt;/P&gt;&lt;P&gt;Part 1.&amp;nbsp; &amp;nbsp; session start is completed&lt;/P&gt;&lt;P&gt;Part 2.&amp;nbsp; &amp;nbsp; &amp;nbsp;Before app message row count&amp;nbsp; &amp;nbsp; : 9000000&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Before app consolidation row count&amp;nbsp; &amp;nbsp; :8888800&lt;/P&gt;&lt;P&gt;Part 3.&amp;nbsp; &amp;nbsp; &amp;nbsp;append message completed&lt;/P&gt;&lt;P&gt;Part 4.&amp;nbsp; &amp;nbsp; &amp;nbsp;After app message flush row count : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;After app message flush row count&amp;nbsp; &amp;nbsp; &amp;nbsp;:1000000&lt;/P&gt;&lt;P&gt;=================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we use regex and get the fields from above event and show them in table like below&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;parts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;message&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Part 1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;session start is completed&lt;/P&gt;&lt;P&gt;part 2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Before app message row count&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;9000000&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;8888800&lt;/P&gt;&lt;P&gt;part 3&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;append message completed&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 09:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Help-to-extract-fields/m-p/678171#M231929</guid>
      <dc:creator>Harikiranjammul</dc:creator>
      <dc:date>2024-02-21T09:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help to extract fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Help-to-extract-fields/m-p/678174#M231932</link>
      <description>&lt;P&gt;Before I invest too much time working on a regex, please can you share your events in a code block &amp;lt;/&amp;gt;. Also, do your events really have "Part" in them? (Regex matches in patterns and unless the patterns are accurate, the match will not be found.)&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 11:11:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Help-to-extract-fields/m-p/678174#M231932</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-02-21T11:11:52Z</dc:date>
    </item>
  </channel>
</rss>

