<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need event extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686278#M234123</link>
    <description>&lt;P&gt;Do you mean to obtain something like this?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;field name&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;field value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Action Name&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Read Input Files GDrive Start&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Record Id Type&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Invoice&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Run Reference&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;xx-0645-11ef-xx-xx&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Task Name&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Cash Apps PAPI&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;applicationName&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;ct-fin-abc-apps-papi-v1-uw2-ut&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;applicationType&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;PAPI&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;applicationVersion&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;1.0.7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;batchSize&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;businessRecordId&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;businessRecordType&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;detailText&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Start Reading Input Files from G drive&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;domain&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;CR C4E&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;endpointSystem&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;environment&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;ct-app-UAT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;region&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;us-ne-2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;remainingRetries&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;stage&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;MILESTONE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;status&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;SUCCESS&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="47px"&gt;threadName&lt;/TD&gt;&lt;TD width="622.984375px" height="47px"&gt;[MuleRuntime].uber.05: [ct-fin-aps-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;timestamp&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;2024-04-29 16:30:08.455&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;totalRecords&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;tx.fileName&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;implementation.xml&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;tx.flow&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;read-input-files-sub-flow&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;txlineNumber&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;71&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;worker&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;x-transaction-id&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;xxxx-e691-xx-91bf-xxx&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;suggested, you should use built-in JSON capability to do the job, not regex. &amp;nbsp;Use rex only to extract the JSON part. &amp;nbsp;Like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "eilog.EILog:\s*(?&amp;lt;eilog&amp;gt;{.+})"
| spath input=eilog
| spath input=jsonRecord&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an emulation of your sample data. &amp;nbsp;Play with it and compare with real data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "INFO 2024-04-29 16:30:08,456 [[MuleRuntime].uber.05: [ct-fin-abc-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333] com.sfdc.it.ei.mule4.eilog.EILog: {\"worker\":\"0\",\"region\":\"us-ne-2\",\"applicationName\":\"ct-fin-abc-apps-papi-v1-uw2-ut\",\"applicationVersion\":\"1.0.7\",\"applicationType\":\"PAPI\",\"environment\":\"ct-app-UAT\",\"domain\":\"CR C4E\",\"x-transaction-id\":\"xxxx-e691-xx-91bf-xxx\",\"tx.flow\":\"read-input-files-sub-flow\",\"tx.fileName\":\"implementation.xml\",\"txlineNumber\":\"71\",\"stage\":\"MILESTONE\",\"status\":\"SUCCESS\",\"endpointSystem\":\"\",\"jsonRecord\":\"{\\n \\\"Task Name\\\": \\\"Cash Apps PAPI\\\",\\n \\\"Action Name\\\": \\\"Read Input Files GDrive Start\\\",\\n \\\"Run Reference\\\": \\\"xx-0645-11ef-xx-xx\\\",\\n \\\"Record Id Type\\\": \\\"Invoice\\\"\\n}\",\"detailText\":\"Start Reading Input Files from G drive\",\"businessRecordId\":\"\",\"businessRecordType\":\"\",\"batchSize\":\"0\",\"totalRecords\":\"0\",\"remainingRetries\":\"0\",\"timestamp\":\"2024-04-29 16:30:08.455\",\"threadName\":\"[MuleRuntime].uber.05: [ct-fin-aps-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333\"}"
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 May 2024 07:52:46 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2024-05-03T07:52:46Z</dc:date>
    <item>
      <title>Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686149#M234102</link>
      <description>&lt;P&gt;I want to extract all the key value pairs from this event&amp;nbsp; dynamically&lt;BR /&gt;Can someone help with the query&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;INFO 2024-04-29 16:30:08,456 [[MuleRuntime].uber.05: [ct-fin-abc-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333] com.sfdc.it.ei.mule4.eilog.EILog: {"worker":"0","region":"us-ne-2","applicationName":"ct-fin-abc-apps-papi-v1-uw2-ut","applicationVersion":"1.0.7","applicationType":"PAPI","environment":"ct-app-UAT","domain":"CR C4E","x-transaction-id":"xxxx-e691-xx-91bf-xxx","tx.flow":"read-input-files-sub-flow","tx.fileName":"implementation.xml","txlineNumber":"71","stage":"MILESTONE","status":"SUCCESS","endpointSystem":"","jsonRecord":"{\n \"Task Name\": \"Cash Apps PAPI\",\n \"Action Name\": \"Read Input Files GDrive Start\",\n \"Run Reference\": \"xx-0645-11ef-xx-xx\",\n \"Record Id Type\": \"Invoice\"\n}","detailText":"Start Reading Input Files from G drive","businessRecordId":"","businessRecordType":"","batchSize":"0","totalRecords":"0","remainingRetries":"0","timestamp":"2024-04-29 16:30:08.455","threadName":"[MuleRuntime].uber.05: [ct-fin-aps-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333"}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 09:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686149#M234102</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-02T09:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686152#M234103</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242882"&gt;@kranthimutyala2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you tried to use the spath command (&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Spath)?" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Spath)?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It automatically recognize all the fields-value pairs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 10:46:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686152#M234103</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-02T10:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686155#M234104</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;tried but it didnt work&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 10:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686155#M234104</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-02T10:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686156#M234105</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242882"&gt;@kranthimutyala2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;which sourcetype are you using?&lt;/P&gt;&lt;P&gt;did you tried json or _json?&lt;/P&gt;&lt;P&gt;In this case the INDEXED_EXTRACTIONS=json is enabled&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 11:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686156#M234105</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-02T11:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686157#M234106</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=abc source="http:clhub-preprod" sourcetype=_json "ct-fin-abc-apps-papi-v1-uw2-ut" "Action Name" | rex field=event "^(?&amp;lt;event_type&amp;gt;\w+)" | where event_type="INFO" | spath input_field=event&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;event field contains the above log data&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 12:04:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686157#M234106</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-02T12:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686167#M234108</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242882"&gt;@kranthimutyala2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what does it happen using only spath:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=abc source="http:clhub-preprod" sourcetype=_json "ct-fin-abc-apps-papi-v1-uw2-ut" "Action Name" 
| spath
| rex field=event "^(?&amp;lt;event_type&amp;gt;\w+)" 
| where event_type="INFO" &lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 12:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686167#M234108</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-02T12:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686172#M234113</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;I dont see any difference, its not extracting anything&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 12:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686172#M234113</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-02T12:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686278#M234123</link>
      <description>&lt;P&gt;Do you mean to obtain something like this?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;field name&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;field value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Action Name&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Read Input Files GDrive Start&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Record Id Type&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Invoice&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Run Reference&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;xx-0645-11ef-xx-xx&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Task Name&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Cash Apps PAPI&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;applicationName&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;ct-fin-abc-apps-papi-v1-uw2-ut&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;applicationType&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;PAPI&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;applicationVersion&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;1.0.7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;batchSize&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;businessRecordId&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;businessRecordType&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;detailText&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Start Reading Input Files from G drive&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;domain&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;CR C4E&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;endpointSystem&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;environment&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;ct-app-UAT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;region&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;us-ne-2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;remainingRetries&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;stage&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;MILESTONE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;status&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;SUCCESS&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="47px"&gt;threadName&lt;/TD&gt;&lt;TD width="622.984375px" height="47px"&gt;[MuleRuntime].uber.05: [ct-fin-aps-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;timestamp&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;2024-04-29 16:30:08.455&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;totalRecords&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;tx.fileName&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;implementation.xml&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;tx.flow&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;read-input-files-sub-flow&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;txlineNumber&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;71&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;worker&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;x-transaction-id&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;xxxx-e691-xx-91bf-xxx&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;suggested, you should use built-in JSON capability to do the job, not regex. &amp;nbsp;Use rex only to extract the JSON part. &amp;nbsp;Like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "eilog.EILog:\s*(?&amp;lt;eilog&amp;gt;{.+})"
| spath input=eilog
| spath input=jsonRecord&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an emulation of your sample data. &amp;nbsp;Play with it and compare with real data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "INFO 2024-04-29 16:30:08,456 [[MuleRuntime].uber.05: [ct-fin-abc-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333] com.sfdc.it.ei.mule4.eilog.EILog: {\"worker\":\"0\",\"region\":\"us-ne-2\",\"applicationName\":\"ct-fin-abc-apps-papi-v1-uw2-ut\",\"applicationVersion\":\"1.0.7\",\"applicationType\":\"PAPI\",\"environment\":\"ct-app-UAT\",\"domain\":\"CR C4E\",\"x-transaction-id\":\"xxxx-e691-xx-91bf-xxx\",\"tx.flow\":\"read-input-files-sub-flow\",\"tx.fileName\":\"implementation.xml\",\"txlineNumber\":\"71\",\"stage\":\"MILESTONE\",\"status\":\"SUCCESS\",\"endpointSystem\":\"\",\"jsonRecord\":\"{\\n \\\"Task Name\\\": \\\"Cash Apps PAPI\\\",\\n \\\"Action Name\\\": \\\"Read Input Files GDrive Start\\\",\\n \\\"Run Reference\\\": \\\"xx-0645-11ef-xx-xx\\\",\\n \\\"Record Id Type\\\": \\\"Invoice\\\"\\n}\",\"detailText\":\"Start Reading Input Files from G drive\",\"businessRecordId\":\"\",\"businessRecordType\":\"\",\"batchSize\":\"0\",\"totalRecords\":\"0\",\"remainingRetries\":\"0\",\"timestamp\":\"2024-04-29 16:30:08.455\",\"threadName\":\"[MuleRuntime].uber.05: [ct-fin-aps-apps-papi-v1-uw2-ut].abc-apps-schedular-main-flow.BLOCKING @68f82333\"}"
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 07:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686278#M234123</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-05-03T07:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686505#M234176</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;this im able to extract but I need field values for Task Name, Action Name, DetailText etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 06:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686505#M234176</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-06T06:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686506#M234177</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Im using&amp;nbsp;rex field=event "{\\n \\"Task Name\\": \\"(?&amp;lt;taskName&amp;gt;[^\"]+)\\""&lt;BR /&gt;its working in Regex101 but not working in Splunk&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 06:42:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686506#M234177</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-06T06:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686508#M234179</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242882"&gt;@kranthimutyala2&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as also&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;hinted, in Splunk you must use three backslashes instead 2 as in regex101:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=event "{\\\n \\\"Task Name\\\": \\"(?&amp;lt;taskName&amp;gt;[^\"]+)"&lt;/LI-CODE&gt;&lt;P&gt;It's a difference: I opened a casefor a different behavios than the documentation, so the documentation was modified! I don't knw why, Splunk Project doesn't want to solve it!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 06:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686508#M234179</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-06T06:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686509#M234180</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Thanks I tried but getting this error&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Error in 'SearchParser': Missing a search command before '^'. Error at position '461' of search query 'search index=abc source="http:clhub-preprod" "bt-f...{snipped} {errorcontext = taskName&amp;gt;[^\"]+)"}'.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 06:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686509#M234180</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-06T06:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686514#M234184</link>
      <description>&lt;P&gt;A more fundamental problem is that by insisting &amp;nbsp;on using regex for this log, you are treating structured JSON log eilog.EILOG as text string. &amp;nbsp;It is NOT. &amp;nbsp; It is much more robust to use Splunk's built-in, QA tested capabilities to handle structured data. &amp;nbsp;Have you tried my suggestion&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "eilog.EILog:\s*(?&amp;lt;eilog&amp;gt;{.+})"
| spath input=eilog
| spath input=jsonRecord&lt;/LI-CODE&gt;&lt;P&gt;and not getting all data fields in this JSON? &amp;nbsp; As I illustrated previously, this should give you&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="162.015625px" height="25px"&gt;Task Name&lt;/TD&gt;&lt;TD width="622.984375px" height="25px"&gt;Cash Apps PAPI&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;along with dozens of other key-value pairs.&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 07:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686514#M234184</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-05-06T07:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686519#M234187</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;it worked thanks&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 07:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686519#M234187</guid>
      <dc:creator>kranthimutyala2</dc:creator>
      <dc:date>2024-05-06T07:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need event extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686536#M234189</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242882"&gt;@kranthimutyala2&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 08:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-event-extraction/m-p/686536#M234189</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-06T08:55:20Z</dc:date>
    </item>
  </channel>
</rss>

