<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Table using regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697621#M236959</link>
    <description>&lt;P&gt;Below is my raw log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;08/28/2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;08:14:50&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;Current&lt;/SPAN&gt; &lt;SPAN class=""&gt;Device&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info&lt;/SPAN&gt; &lt;SPAN class=""&gt;...&lt;/SPAN&gt;&lt;SPAN&gt; ****************************************************************************** &lt;/SPAN&gt;&lt;SPAN class=""&gt;Current&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mode:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Skull&lt;/SPAN&gt; &lt;SPAN class=""&gt;Teams&lt;/SPAN&gt; &lt;SPAN class=""&gt;Current&lt;/SPAN&gt; &lt;SPAN class=""&gt;Device&lt;/SPAN&gt; &lt;SPAN class=""&gt;name:&lt;/SPAN&gt;&amp;nbsp;xxxxx&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Environment&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;:1.00.00.004&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Firmware&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;.&lt;SPAN class=""&gt;17&lt;/SPAN&gt;.&lt;SPAN class=""&gt;00&lt;/SPAN&gt;.&lt;SPAN class=""&gt;040&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Flex-Hub&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;:1.3.0127.00204&lt;/SPAN&gt; &lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;HD-CONV-USB-200&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;:009.051&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want extract only&amp;nbsp; :&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Firmware&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; :xx.xx.xxx&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wrote a query like bleow , but not working , pls help&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=123 sourcetype = teams
| search "Crestron Package Firmware version :"
| rex field=_raw ":\s+(?&amp;lt;CCSFirmware&amp;gt;.*?)$"
| eval Time(utc)=strftime(_time, "%y-%m-%d %H:%M:%S")
| table host Time(utc) CCSFirmware&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 19:01:13 GMT</pubDate>
    <dc:creator>VRP136</dc:creator>
    <dc:date>2024-08-29T19:01:13Z</dc:date>
    <item>
      <title>Table using regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697621#M236959</link>
      <description>&lt;P&gt;Below is my raw log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;08/28/2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;08:14:50&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;Current&lt;/SPAN&gt; &lt;SPAN class=""&gt;Device&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info&lt;/SPAN&gt; &lt;SPAN class=""&gt;...&lt;/SPAN&gt;&lt;SPAN&gt; ****************************************************************************** &lt;/SPAN&gt;&lt;SPAN class=""&gt;Current&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mode:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Skull&lt;/SPAN&gt; &lt;SPAN class=""&gt;Teams&lt;/SPAN&gt; &lt;SPAN class=""&gt;Current&lt;/SPAN&gt; &lt;SPAN class=""&gt;Device&lt;/SPAN&gt; &lt;SPAN class=""&gt;name:&lt;/SPAN&gt;&amp;nbsp;xxxxx&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Environment&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;:1.00.00.004&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Firmware&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; :&lt;/SPAN&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;.&lt;SPAN class=""&gt;17&lt;/SPAN&gt;.&lt;SPAN class=""&gt;00&lt;/SPAN&gt;.&lt;SPAN class=""&gt;040&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Flex-Hub&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;:1.3.0127.00204&lt;/SPAN&gt; &lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;HD-CONV-USB-200&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;:009.051&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want extract only&amp;nbsp; :&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Crestron&lt;/SPAN&gt; &lt;SPAN class=""&gt;Package&lt;/SPAN&gt; &lt;SPAN class=""&gt;Firmware&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; :xx.xx.xxx&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wrote a query like bleow , but not working , pls help&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=123 sourcetype = teams
| search "Crestron Package Firmware version :"
| rex field=_raw ":\s+(?&amp;lt;CCSFirmware&amp;gt;.*?)$"
| eval Time(utc)=strftime(_time, "%y-%m-%d %H:%M:%S")
| table host Time(utc) CCSFirmware&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697621#M236959</guid>
      <dc:creator>VRP136</dc:creator>
      <dc:date>2024-08-29T19:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Table using regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697627#M236964</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=123 sourcetype = teams
| search "Crestron Package Firmware version :"
| rex field=_raw "Crestron Package Firmware version :\s+(?&amp;lt;CCSFirmware&amp;gt;\S*?)"
| eval Time(utc)=strftime(_time, "%y-%m-%d %H:%M:%S")
| table host Time(utc) CCSFirmware&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 28 Aug 2024 15:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697627#M236964</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-28T15:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Table using regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697714#M236992</link>
      <description>&lt;P&gt;No luck ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VRP136_0-1724937748453.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32460iFBC28301B96909A3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VRP136_0-1724937748453.png" alt="VRP136_0-1724937748453.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 13:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697714#M236992</guid>
      <dc:creator>VRP136</dc:creator>
      <dc:date>2024-08-29T13:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Table using regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697728#M236994</link>
      <description>&lt;P&gt;Try this inside the quotes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Crestron Package Firmware version :(?&amp;lt;CCSFirmware&amp;gt;[^\s]+)&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 15:38:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697728#M236994</guid>
      <dc:creator>dural_yyz24</dc:creator>
      <dc:date>2024-08-29T15:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Table using regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697746#M236999</link>
      <description>&lt;P&gt;Looks like there may not be a space after the colon so use * instead of +&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "Crestron Package Firmware version :\s*(?&amp;lt;CCSFirmware&amp;gt;\S*?)"&lt;/LI-CODE&gt;&lt;P&gt;It would help if you share your event data in a code block so that formatting e.g. spaces are preserved&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:12:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697746#M236999</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-29T18:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Table using regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697757#M237004</link>
      <description>&lt;P&gt;This worked , Thank you so much&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265467"&gt;@dural_yyz24&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-using-regex/m-p/697757#M237004</guid>
      <dc:creator>VRP136</dc:creator>
      <dc:date>2024-08-29T19:47:13Z</dc:date>
    </item>
  </channel>
</rss>

