<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need rex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-rex/m-p/681274#M232808</link>
    <description>&lt;P&gt;Sample Logs:&lt;/P&gt;&lt;PRE&gt;&amp;lt;&amp;lt;&amp;lt; Reporting.logs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.SampleDBinternalexternal:::XII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 34567d34-1245-4asd-a27f-42345cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; Applicationlogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.AccountBinding:::XIS KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 7854d34-7623-4asd-a27f-90864cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; IntialLogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.IntialReortbinding:::XIP KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 12345d34-1288-8asd-a26f-42348cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; PartialReportingLogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.totalDBinternalexternal:::XII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 09876d34-6753-3asd-a30f-87654cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; FailedLogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.SampleDBinternalexternal:::ZII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 56744d34-1245-4asd-a11f-89765cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; Reporting.logs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.notalwayslogs:::PII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 89765d34-9875-4asd-a2f-87654cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am not sure how to write rex to do field extraction.&amp;nbsp;please find the below screenshot, i need rex for the highlighted ones:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mahesh27_0-1710885534170.png" style="width: 480px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29813i04BD811E0BB0D56F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mahesh27_0-1710885534170.png" alt="mahesh27_0-1710885534170.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2024 22:00:13 GMT</pubDate>
    <dc:creator>mahesh27</dc:creator>
    <dc:date>2024-03-19T22:00:13Z</dc:date>
    <item>
      <title>Need rex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-rex/m-p/681274#M232808</link>
      <description>&lt;P&gt;Sample Logs:&lt;/P&gt;&lt;PRE&gt;&amp;lt;&amp;lt;&amp;lt; Reporting.logs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.SampleDBinternalexternal:::XII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 34567d34-1245-4asd-a27f-42345cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; Applicationlogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.AccountBinding:::XIS KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 7854d34-7623-4asd-a27f-90864cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; IntialLogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.IntialReortbinding:::XIP KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 12345d34-1288-8asd-a26f-42348cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; PartialReportingLogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.totalDBinternalexternal:::XII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 09876d34-6753-3asd-a30f-87654cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; FailedLogs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.SampleDBinternalexternal:::ZII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 56744d34-1245-4asd-a11f-89765cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters

&amp;lt;&amp;lt;&amp;lt; Reporting.logs : 2454 : 15671231232345:INFO     :com.am.sss.inws.sample.connector.notalwayslogs:::PII KEY:: g67a124-6f55-433a-345aexwc vx:: REQS REQUID :: 89765d34-9875-4asd-a2f-87654cvdwwxz:: SUB REQUID:: 7866-ghnb5-33333:: Application :barcode! company :: Org : Branch-loc :: TIME:&amp;lt;TIMESTAMP&amp;gt; (12) 2022/01/22 17:17:58:208 to 17:17:58:212 4 ms Generic BF Invoice time for one statment with parameters&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am not sure how to write rex to do field extraction.&amp;nbsp;please find the below screenshot, i need rex for the highlighted ones:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mahesh27_0-1710885534170.png" style="width: 480px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29813i04BD811E0BB0D56F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mahesh27_0-1710885534170.png" alt="mahesh27_0-1710885534170.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 22:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-rex/m-p/681274#M232808</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2024-03-19T22:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need rex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-rex/m-p/681288#M232815</link>
      <description>&lt;P&gt;Something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "&amp;lt;&amp;lt;&amp;lt;\s*(?&amp;lt;LogType&amp;gt;[^\s]*)\s*:[^:]*:[^:]*:[^:]*:(?&amp;lt;Class&amp;gt;[^:]*).*REQS REQUID\s*::\s*(?&amp;lt;ReqsRequid&amp;gt;[^:]*).*SUB REQUID::\s*(?&amp;lt;SubRequid&amp;gt;[^:]*).*Application\s*:(?&amp;lt;Application&amp;gt;[^:]*::\s*Org\s*:\s*(?&amp;lt;Org&amp;gt;[^:]*)"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 19 Mar 2024 23:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-rex/m-p/681288#M232815</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-03-19T23:22:27Z</dc:date>
    </item>
  </channel>
</rss>

