<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need help to extract field from raw in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743504#M241093</link>
    <description>&lt;P&gt;Please find the below attached screenshot and data sample i need to create 5 felids&amp;nbsp;&lt;BR /&gt;problem statement - old splunk query not working as logging pattern got changed&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;3/28/25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10:04:25.685 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;2025-03-28T22:04:25.685Z&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; --&lt;SPAN class=""&gt;-&lt;/SPAN&gt; [&lt;SPAN class=""&gt;ool-1-thread-11&lt;/SPAN&gt;] &lt;SPAN class=""&gt;c.d.t.l.s.s.e.e.NoopLoggingEtlEndpoint&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Completed&lt;/SPAN&gt; &lt;SPAN class=""&gt;generation&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;[&lt;STRONG&gt;&lt;SPAN class=""&gt;DE&lt;/SPAN&gt;, &lt;SPAN class=""&gt;2025-03-28&lt;/SPAN&gt;, &lt;SPAN class=""&gt;LOAN_EVENT_SDP&lt;/SPAN&gt;&lt;/STRONG&gt;, &lt;SPAN class=""&gt;1&lt;/SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Number&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;records:&lt;/SPAN&gt; &lt;SPAN class=""&gt;186&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="lonhybridapp03.uk.db.com" href="https://splunk-hc-prod-uk.intranet.db.com:8000/en-US/app/ls2/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20NOT%20Audit%20app%3D%22ls2-intraday-sdp%22%20%22Completed%20generation%20for%22%20%22%5BDE%2C%202025-03-28%2C%20*%2C%201%5D%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;sid=1743765333.1742667_7B165ACC-B863-4EFA-8DCF-FD7F603AC155&amp;amp;display.events.type=list#" target="_blank" rel="noopener"&gt;lonhybridapp03.uk.db.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="/var/log/pods/ls2_ls2-intraday-sdp-86854ff574-48dgp_830e2ef9-56be-4996-ae21-127366a78515/ls2-intraday-sdp/0.log" href="https://splunk-hc-prod-uk.intranet.db.com:8000/en-US/app/ls2/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20NOT%20Audit%20app%3D%22ls2-intraday-sdp%22%20%22Completed%20generation%20for%22%20%22%5BDE%2C%202025-03-28%2C%20*%2C%201%5D%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;sid=1743765333.1742667_7B165ACC-B863-4EFA-8DCF-FD7F603AC155&amp;amp;display.events.type=list#" target="_blank" rel="noopener"&gt;/var/log/pods/ls2_ls2-intraday-sdp-86854ff574-48dgp_830e2ef9-56be-4996-ae21-127366a78515/ls2-intraday-sdp/0.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="kube:container:ls2-intraday-sdp" href="https://splunk-hc-prod-uk.intranet.db.com:8000/en-US/app/ls2/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20NOT%20Audit%20app%3D%22ls2-intraday-sdp%22%20%22Completed%20generation%20for%22%20%22%5BDE%2C%202025-03-28%2C%20*%2C%201%5D%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;sid=1743765333.1742667_7B165ACC-B863-4EFA-8DCF-FD7F603AC155&amp;amp;display.events.type=list#" target="_blank" rel="noopener"&gt;kube:container:ls2-intraday-sdp&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=*1644* container_name="ls2-sdp-java" $selected_countries$&lt;BR /&gt;| rex field=_raw "country=(?P&amp;lt;country&amp;gt;\w+)"&amp;nbsp; &amp;nbsp; &lt;STRONG&gt;(DE)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "sdpType=(?P&amp;lt;sdpType&amp;gt;\w+)"&amp;nbsp; &lt;STRONG&gt;(&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;LOAN_EVENT_SDP&lt;/SPAN&gt;&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "cobDate=(?P&amp;lt;cobDate&amp;gt;\w+)"&amp;nbsp; &lt;STRONG&gt;(&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;2025-03-28&lt;/SPAN&gt;&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "record-count: (?P&amp;lt;Recordcount&amp;gt;\w+)" &lt;STRONG&gt;(&lt;SPAN class=""&gt;186&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "\[(?&amp;lt;dateTime&amp;gt;.*)\] \{Thread"&amp;nbsp; &lt;STRONG&gt;(&lt;SPAN class=""&gt;2025-03-28T22:04&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| eval DateTime=strptime(dateTime, "%Y-%m-%dT%H:%M:%S,%N")&lt;BR /&gt;| eval CreatedTime=strftime(DateTime, "%H:%M")&lt;BR /&gt;| eval CreatedDate=strftime(DateTime, "%Y-%m-%d")&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;above SPL has old query , can you please help me with new rex pattern to extract these fields&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For clear understanding i have attached required fields in screenshot&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhaskar5428_0-1743766654553.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38448i5BD48CA6C66EB6D2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhaskar5428_0-1743766654553.png" alt="bhaskar5428_0-1743766654553.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Apr 2025 11:38:33 GMT</pubDate>
    <dc:creator>bhaskar5428</dc:creator>
    <dc:date>2025-04-04T11:38:33Z</dc:date>
    <item>
      <title>Need help to extract field from raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743504#M241093</link>
      <description>&lt;P&gt;Please find the below attached screenshot and data sample i need to create 5 felids&amp;nbsp;&lt;BR /&gt;problem statement - old splunk query not working as logging pattern got changed&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;3/28/25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10:04:25.685 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;2025-03-28T22:04:25.685Z&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; --&lt;SPAN class=""&gt;-&lt;/SPAN&gt; [&lt;SPAN class=""&gt;ool-1-thread-11&lt;/SPAN&gt;] &lt;SPAN class=""&gt;c.d.t.l.s.s.e.e.NoopLoggingEtlEndpoint&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Completed&lt;/SPAN&gt; &lt;SPAN class=""&gt;generation&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;[&lt;STRONG&gt;&lt;SPAN class=""&gt;DE&lt;/SPAN&gt;, &lt;SPAN class=""&gt;2025-03-28&lt;/SPAN&gt;, &lt;SPAN class=""&gt;LOAN_EVENT_SDP&lt;/SPAN&gt;&lt;/STRONG&gt;, &lt;SPAN class=""&gt;1&lt;/SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Number&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;records:&lt;/SPAN&gt; &lt;SPAN class=""&gt;186&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="lonhybridapp03.uk.db.com" href="https://splunk-hc-prod-uk.intranet.db.com:8000/en-US/app/ls2/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20NOT%20Audit%20app%3D%22ls2-intraday-sdp%22%20%22Completed%20generation%20for%22%20%22%5BDE%2C%202025-03-28%2C%20*%2C%201%5D%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;sid=1743765333.1742667_7B165ACC-B863-4EFA-8DCF-FD7F603AC155&amp;amp;display.events.type=list#" target="_blank" rel="noopener"&gt;lonhybridapp03.uk.db.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="/var/log/pods/ls2_ls2-intraday-sdp-86854ff574-48dgp_830e2ef9-56be-4996-ae21-127366a78515/ls2-intraday-sdp/0.log" href="https://splunk-hc-prod-uk.intranet.db.com:8000/en-US/app/ls2/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20NOT%20Audit%20app%3D%22ls2-intraday-sdp%22%20%22Completed%20generation%20for%22%20%22%5BDE%2C%202025-03-28%2C%20*%2C%201%5D%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;sid=1743765333.1742667_7B165ACC-B863-4EFA-8DCF-FD7F603AC155&amp;amp;display.events.type=list#" target="_blank" rel="noopener"&gt;/var/log/pods/ls2_ls2-intraday-sdp-86854ff574-48dgp_830e2ef9-56be-4996-ae21-127366a78515/ls2-intraday-sdp/0.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="kube:container:ls2-intraday-sdp" href="https://splunk-hc-prod-uk.intranet.db.com:8000/en-US/app/ls2/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20NOT%20Audit%20app%3D%22ls2-intraday-sdp%22%20%22Completed%20generation%20for%22%20%22%5BDE%2C%202025-03-28%2C%20*%2C%201%5D%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;sid=1743765333.1742667_7B165ACC-B863-4EFA-8DCF-FD7F603AC155&amp;amp;display.events.type=list#" target="_blank" rel="noopener"&gt;kube:container:ls2-intraday-sdp&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=*1644* container_name="ls2-sdp-java" $selected_countries$&lt;BR /&gt;| rex field=_raw "country=(?P&amp;lt;country&amp;gt;\w+)"&amp;nbsp; &amp;nbsp; &lt;STRONG&gt;(DE)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "sdpType=(?P&amp;lt;sdpType&amp;gt;\w+)"&amp;nbsp; &lt;STRONG&gt;(&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;LOAN_EVENT_SDP&lt;/SPAN&gt;&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "cobDate=(?P&amp;lt;cobDate&amp;gt;\w+)"&amp;nbsp; &lt;STRONG&gt;(&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;2025-03-28&lt;/SPAN&gt;&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "record-count: (?P&amp;lt;Recordcount&amp;gt;\w+)" &lt;STRONG&gt;(&lt;SPAN class=""&gt;186&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| rex field=_raw "\[(?&amp;lt;dateTime&amp;gt;.*)\] \{Thread"&amp;nbsp; &lt;STRONG&gt;(&lt;SPAN class=""&gt;2025-03-28T22:04&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;BR /&gt;| eval DateTime=strptime(dateTime, "%Y-%m-%dT%H:%M:%S,%N")&lt;BR /&gt;| eval CreatedTime=strftime(DateTime, "%H:%M")&lt;BR /&gt;| eval CreatedDate=strftime(DateTime, "%Y-%m-%d")&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;above SPL has old query , can you please help me with new rex pattern to extract these fields&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For clear understanding i have attached required fields in screenshot&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhaskar5428_0-1743766654553.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38448i5BD48CA6C66EB6D2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhaskar5428_0-1743766654553.png" alt="bhaskar5428_0-1743766654553.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 11:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743504#M241093</guid>
      <dc:creator>bhaskar5428</dc:creator>
      <dc:date>2025-04-04T11:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to extract field from raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743507#M241095</link>
      <description>&lt;P&gt;Perhaps this will help.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=*1644* container_name="ls2-sdp-java" $selected_countries$
| rex field=_raw "for \[(?P&amp;lt;country&amp;gt;\w+),\s*(?P&amp;lt;cobDate&amp;gt;\w+),\s*(?P&amp;lt;sdpType&amp;gt;\w+)"
| rex field=_raw "records: (?P&amp;lt;Recordcount&amp;gt;\w+)"
| rex field=_raw "^(?&amp;lt;dateTime&amp;gt;\S+)"
| eval DateTime=strptime(dateTime, "%Y-%m-%dT%H:%M:%S.%3N%Z")
| eval CreatedTime=strftime(DateTime, "%H:%M")
| eval CreatedDate=strftime(DateTime, "%Y-%m-%d")&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 04 Apr 2025 13:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743507#M241095</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-04T13:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to extract field from raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743516#M241098</link>
      <description>&lt;P&gt;Not working , But if use single and try for single Country its working&amp;nbsp;&lt;BR /&gt;please help&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhaskar5428_0-1743769239520.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38450i653F129C7F10AA7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhaskar5428_0-1743769239520.png" alt="bhaskar5428_0-1743769239520.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhaskar5428_1-1743769275246.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38451i89621C7BB80848A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhaskar5428_1-1743769275246.png" alt="bhaskar5428_1-1743769275246.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;also what is use of&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;| rex field=_raw "^\S+"&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 12:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743516#M241098</guid>
      <dc:creator>bhaskar5428</dc:creator>
      <dc:date>2025-04-04T12:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to extract field from raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743519#M241099</link>
      <description>&lt;P&gt;Not working , please help&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;| rex field=_raw "^\S+"&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhaskar5428_0-1743769391319.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38453iDA39A5B8DD630C00/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhaskar5428_0-1743769391319.png" alt="bhaskar5428_0-1743769391319.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhaskar5428_1-1743769432164.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38454i542D586FDB5CA4E7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhaskar5428_1-1743769432164.png" alt="bhaskar5428_1-1743769432164.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 12:24:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743519#M241099</guid>
      <dc:creator>bhaskar5428</dc:creator>
      <dc:date>2025-04-04T12:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to extract field from raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743525#M241102</link>
      <description>&lt;P&gt;Please try my updated query.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 13:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743525#M241102</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-04T13:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to extract field from raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743566#M241115</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244235"&gt;@bhaskar5428&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Check out the following:&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=*1644* container_name="ls2-sdp-java" $selected_countries$ 
| rex field=_raw "\[(?&amp;lt;country&amp;gt;[^,]+),\s(?&amp;lt;cobDate&amp;gt;[^,]+),\s(?&amp;lt;sdpType&amp;gt;[^,]+)," 
| rex field=_raw "Number of records:\s*(?&amp;lt;Recordcount&amp;gt;\d+)" 
| rex field=_raw "^(?&amp;lt;dateTime&amp;gt;\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d+Z)" 
| eval DateTime=strptime(dateTime, "%Y-%m-%dT%H:%M:%S.%NZ") 
| eval CreatedTime=strftime(DateTime, "%H:%M") 
| eval CreatedDate=strftime(DateTime, "%Y-%m-%d")&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;Example with makeresults:&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="2025-03-28T22:04:25.685Z INFO 1 --- [ool-1-thread-11] c.d.t.l.s.s.e.e.NoopLoggingEtlEndpoint : Completed generation for [DE, 2025-03-28, LOAN_EVENT_SDP, 1]. Number of records: 186" 
| rex field=_raw "\[(?&amp;lt;country&amp;gt;[^,]+),\s(?&amp;lt;cobDate&amp;gt;[^,]+),\s(?&amp;lt;sdpType&amp;gt;[^,]+)," 
| rex field=_raw "Number of records:\s*(?&amp;lt;Recordcount&amp;gt;\d+)" 
| rex field=_raw "^(?&amp;lt;dateTime&amp;gt;\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d+Z)" 
| eval DateTime=strptime(dateTime, "%Y-%m-%dT%H:%M:%S.%NZ") 
| eval CreatedTime=strftime(DateTime, "%H:%M") 
| eval CreatedDate=strftime(DateTime, "%Y-%m-%d") 
| table _raw dateTime country cobDate sdpType Recordcount CreatedTime CreatedDate&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt; If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding kudos to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Apr 2025 22:22:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-to-extract-field-from-raw/m-p/743566#M241115</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-04T22:22:38Z</dc:date>
    </item>
  </channel>
</rss>

