<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field Extract returns different results than inline rex field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149651#M41872</link>
    <description>&lt;P&gt;In &lt;CODE&gt;rex&lt;/CODE&gt; &lt;CODE&gt;\"&lt;/CODE&gt; is an escaped double quote, in the field extraction config it's a backslash followed by a double quote - there's no need to escape the double quote because it's not inside a double-quoted string. Additionally it seems your field extraction config is missing the field names inside the capturing groups.&lt;/P&gt;

&lt;P&gt;Another unrelated thought, consider using &lt;CODE&gt;\s*&lt;/CODE&gt; instead of &lt;CODE&gt;.*&lt;/CODE&gt; to jump the gap between your string and the quoted field value, the &lt;CODE&gt;.*&lt;/CODE&gt; greedily matches everything which can lead to unexpected results both in &lt;CODE&gt;rex&lt;/CODE&gt; and field extraction config.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Dec 2014 22:31:44 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-12-11T22:31:44Z</dc:date>
    <item>
      <title>Field Extract returns different results than inline rex field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149650#M41871</link>
      <description>&lt;P&gt;Using Splunk 6.2,&lt;/P&gt;

&lt;P&gt;I have a few regex commands that return drastically different results when they are set up using field extractions vs inline seach commands. For example,&lt;/P&gt;

&lt;P&gt;Example Log File:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;20140915171053989759850769-27156-8.0.0  --Portfolio "MASTER LONG" --PeriodStartDate "January 1, 2014 12:00:00 am" --PeriodEndDate   "September 15, 2014 11:59:59 pm"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Search command (works correctly):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rex field=_raw "\bPeriodStartDate.*\"(?&amp;lt;PeriodStart&amp;gt;.*)\"" 
|rex field=_raw "\bPeriodEndDate.*\"(?&amp;lt;PeriodEnd&amp;gt;.*)\""
|rex field=_raw "\bPortfolio.*\"(?&amp;lt;Portfolio&amp;gt;.*)\""
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Field Extractions: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\bPeriodEndDate.*\"(?.*)\" 
\bPeriodStartDate.*\"(?.*)\" 
\bPortfolio.*\"(?.*)\" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Could I be doing something wrong in the Field Extractions? I used the same regex in Splunk 6.0 with no issues. Any help would be appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2014 16:52:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149650#M41871</guid>
      <dc:creator>coshea</dc:creator>
      <dc:date>2014-12-11T16:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extract returns different results than inline rex field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149651#M41872</link>
      <description>&lt;P&gt;In &lt;CODE&gt;rex&lt;/CODE&gt; &lt;CODE&gt;\"&lt;/CODE&gt; is an escaped double quote, in the field extraction config it's a backslash followed by a double quote - there's no need to escape the double quote because it's not inside a double-quoted string. Additionally it seems your field extraction config is missing the field names inside the capturing groups.&lt;/P&gt;

&lt;P&gt;Another unrelated thought, consider using &lt;CODE&gt;\s*&lt;/CODE&gt; instead of &lt;CODE&gt;.*&lt;/CODE&gt; to jump the gap between your string and the quoted field value, the &lt;CODE&gt;.*&lt;/CODE&gt; greedily matches everything which can lead to unexpected results both in &lt;CODE&gt;rex&lt;/CODE&gt; and field extraction config.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2014 22:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149651#M41872</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-12-11T22:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extract returns different results than inline rex field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149652#M41873</link>
      <description>&lt;P&gt;The missing field names inside the capture groups was a bit of a copy and paste error. Here is what I have now:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\bPeriodEndDate.*"(?&amp;lt;PeriodEnd&amp;gt;.*)" 
\bPeriodStartDate.*"(?&amp;lt;PeriodStart&amp;gt;.*)" 
\bPortfolio.*"(?&amp;lt;Portfolio&amp;gt;.*)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I got rid of the escaped double quote but still can't get it working. If I use &lt;CODE&gt;\s*&lt;/CODE&gt;  it returns the whole log. But if I use &lt;CODE&gt;.*&lt;/CODE&gt; it returns every event inside of the double quotes.&lt;/P&gt;

&lt;P&gt;Thank you for the help&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2014 20:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149652#M41873</guid>
      <dc:creator>coshea</dc:creator>
      <dc:date>2014-12-18T20:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extract returns different results than inline rex field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149653#M41874</link>
      <description>&lt;P&gt;I observed that your solution (above) always captures the end date.  Adding \s* as martin suggested does capture everything to the end as you noted.  My solution captures exactly what you want efficiently:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-+PeriodEndDate\s+"(?&amp;lt;PeriodEnd&amp;gt;[^"]+)"
-+PeriodStartDate\s+"(?&amp;lt;PeriodStart&amp;gt;[^"]+)"
-+Portfolio\s+"(?&amp;lt;Portfolio&amp;gt;[^"]+)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 04 Sep 2015 12:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extract-returns-different-results-than-inline-rex-field/m-p/149653#M41874</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2015-09-04T12:51:53Z</dc:date>
    </item>
  </channel>
</rss>

