<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use rex to remove the domain from the &amp;quot;User name&amp;quot; field and use the username only as a named extraction? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153790#M43186</link>
    <description>&lt;P&gt;Please accept the answer.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Oct 2014 10:54:38 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2014-10-07T10:54:38Z</dc:date>
    <item>
      <title>How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153774#M43170</link>
      <description>&lt;P&gt;How do I use regex within search to remove the domain from the field "User name" and use the username only as named extraction.&lt;/P&gt;

&lt;P&gt;domain\username&lt;/P&gt;

&lt;P&gt;something like this i think but don't know who to write regex to extract username or extract everything after "\" from field "User name"&lt;/P&gt;

&lt;P&gt;| rex field="User name" "" | eval UserName=lower(UserName) | where UserName=lower(UserName) | search UserName="*"&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:12:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153774#M43170</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T00:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153775#M43171</link>
      <description>&lt;P&gt;What separates domain from username?  Please share a sample of your data.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153775#M43171</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T00:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153776#M43172</link>
      <description>&lt;P&gt;just "\"&lt;/P&gt;

&lt;P&gt;"User name"=domain\username&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:29:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153776#M43172</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T00:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153777#M43173</link>
      <description>&lt;P&gt;Just what?  If there's a character between the quotation marks, it's not showing up.  Escape the character or use backtics.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:32:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153777#M43173</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T00:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153778#M43174</link>
      <description>&lt;P&gt;editor is removing backward slash&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153778#M43174</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T00:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153779#M43175</link>
      <description>&lt;PRE&gt;&lt;CODE&gt; domain\username
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:36:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153779#M43175</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T00:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153780#M43176</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex field="User name" "(?&amp;lt;domain&amp;gt;\S+)\\\\(?&amp;lt;userName&amp;gt;\S+)" | eval userName=lower(userName) | ...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If Splunk doesn't like a field name with a space in it, try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval domainUsername="User name" | rex field=domainUsername "(?&amp;lt;domain&amp;gt;\S+)\\\\(?&amp;lt;userName&amp;gt;\S+)" | eval userName=lower(userName) | ...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:43:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153780#M43176</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T00:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153781#M43177</link>
      <description>&lt;P&gt;getting an error as below. domain includes &lt;CODE&gt;domain-22\username&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Error in 'rex' command: Encountered the following error while compiling the regex '(?&amp;lt;domain-22&amp;gt;\S+)\(?&amp;lt;userName&amp;gt;\S+)': Regex: unmatched parentheses 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153781#M43177</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T00:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153782#M43178</link>
      <description>&lt;P&gt;The parts between &lt;CODE&gt;&amp;lt;&lt;/CODE&gt; and &lt;CODE&gt;&amp;gt;&lt;/CODE&gt; define a Splunk field into which rex will extract matches.  They're not placeholders.  Change "domain-22" back to "domain" and it should work.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 00:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153782#M43178</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T00:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153783#M43179</link>
      <description>&lt;P&gt;still getting same error. tried both options above&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Error in 'rex' command: Encountered the following error while compiling the regex '(?&amp;lt;domain&amp;gt;\S+)\(?&amp;lt;userName&amp;gt;\S+)': Regex: unmatched parentheses 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 07 Oct 2014 01:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153783#M43179</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T01:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153784#M43180</link>
      <description>&lt;P&gt;The backslash needs to be escaped.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 01:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153784#M43180</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T01:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153785#M43181</link>
      <description>&lt;P&gt;only using this.. no luck&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rex field=domainUsername "(?&amp;lt;domain&amp;gt;\S+)\\(?&amp;lt;userName&amp;gt;\S+)" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 07 Oct 2014 01:33:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153785#M43181</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T01:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153786#M43182</link>
      <description>&lt;P&gt;What do you get?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 02:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153786#M43182</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T02:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153787#M43183</link>
      <description>&lt;P&gt;same error above&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 02:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153787#M43183</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T02:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153788#M43184</link>
      <description>&lt;P&gt;The escape character needs to be escaped.  I've updated the answer.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 02:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153788#M43184</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T02:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153789#M43185</link>
      <description>&lt;P&gt;works like a charm.. thank you !&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 03:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153789#M43185</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-07T03:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153790#M43186</link>
      <description>&lt;P&gt;Please accept the answer.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 10:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153790#M43186</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-07T10:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153791#M43187</link>
      <description>&lt;P&gt;yes i did. &lt;/P&gt;

&lt;P&gt;just so i learn how to write regex, if it was seperated by &lt;CODE&gt;:&lt;/CODE&gt; what would i replace it with ?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2014 02:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153791#M43187</guid>
      <dc:creator>kris99</dc:creator>
      <dc:date>2014-10-08T02:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to use rex to remove the domain from the "User name" field and use the username only as a named extraction?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153792#M43188</link>
      <description>&lt;P&gt;In the regex in the answer, the four backslashes are the separator between the domain and username.  If the separator becomes ':' then the regex becomes &lt;CODE&gt;"(?\S+):(?\S+)"&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;A good way to learn is through experimentation.  Try &lt;A href="http://regexr.com/"&gt;regexr&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2014 02:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-rex-to-remove-the-domain-from-the-quot-User-name-quot/m-p/153792#M43188</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-10-08T02:48:34Z</dc:date>
    </item>
  </channel>
</rss>

