<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I write the regex to extract fields from another existing field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206550#M60139</link>
    <description>&lt;P&gt;sql_where_clause is the existing_field&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 07:10:52 GMT</pubDate>
    <dc:creator>skender27</dc:creator>
    <dc:date>2020-09-29T07:10:52Z</dc:date>
    <item>
      <title>How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206539#M60128</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I need to extract a field from another field, no metadata fields.&lt;/P&gt;

&lt;P&gt;The existing field (let's call it &lt;EM&gt;existing_field&lt;/EM&gt;) has the following value:&lt;BR /&gt;
&lt;STRONG&gt;class&lt;/STRONG&gt; = 'blablabla' AND &lt;STRONG&gt;category&lt;/STRONG&gt; = 'blablabla' AND ...&lt;/P&gt;

&lt;P&gt;As you see the new two fields I need to extract are &lt;STRONG&gt;class&lt;/STRONG&gt; and &lt;STRONG&gt;category&lt;/STRONG&gt; and they are separated from &lt;STRONG&gt;AND&lt;/STRONG&gt;.&lt;BR /&gt;
What is the regex to extract them so I can add it to the .conf file?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Skender&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 14:18:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206539#M60128</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2015-09-07T14:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206540#M60129</link>
      <description>&lt;P&gt;Can you give a sample of a whole event?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 14:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206540#M60129</guid>
      <dc:creator>lquinn</dc:creator>
      <dc:date>2015-09-07T14:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206541#M60130</link>
      <description>&lt;P&gt;You could use the &lt;CODE&gt;rex&lt;/CODE&gt; command&lt;BR /&gt;
&lt;CODE&gt;your_search_here | rex field=existing_field "^.*\= '(?\w+)'.*\= '(?\w+)'.*$"&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;More details on the command can be found here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/SearchReference/rex"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/SearchReference/rex&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Otherwise try to use the graphical field extractor: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Knowledge/ExtractfieldsinteractivelywithIFX"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Knowledge/ExtractfieldsinteractivelywithIFX&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 14:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206541#M60130</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2015-09-07T14:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206542#M60131</link>
      <description>&lt;P&gt;Ok I wrote this one and it works for the sample:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;^(?P\w+)\s\=\s\'\w+\s\w+\s\w+\'\sAND(?P\s\w+)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here you have the sample text:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;NAME OF THE FIELD
existing_field_from_json
VALUE
class = 'kdjaldja' AND category = 'shdgahgdhadgjad' AND some_other_text_here... 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now, how to put this regex to extract the information from the existing field?&lt;BR /&gt;
And how to insert the eval stanza in the props.conf?&lt;/P&gt;

&lt;P&gt;Skender&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 15:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206542#M60131</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2015-09-07T15:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206543#M60132</link>
      <description>&lt;P&gt;Here is a sample of the data Iquinn:&lt;BR /&gt;
"existing_field": "&lt;STRONG&gt;class&lt;/STRONG&gt; = 'jhaskjdhsakjdhsakjdh' AND &lt;STRONG&gt;category&lt;/STRONG&gt; = 'dhjkashdjkahdkajhdkaj' AND (hdsgahsdgasdgadgjjasgdhagdhasgd"...&lt;/P&gt;

&lt;P&gt;as far as I know this is part of JSON data...&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Skender&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 15:13:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206543#M60132</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2015-09-07T15:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206544#M60133</link>
      <description>&lt;P&gt;I added in the sourcetype in my props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-my_extraction = (?P\w+)\s\=\s\'\w+\s\w+\s\w+\'\sAND\s(?P\w+) in existing_field
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but I do not see the new fields yet...&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 15:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206544#M60133</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2015-09-07T15:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206545#M60134</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex field=existing_field "class = '(?P&amp;lt;class&amp;gt;\w+)' AND category = '(?P&amp;lt;category&amp;gt;\w+)'" | ...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 07 Sep 2015 15:46:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206545#M60134</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-09-07T15:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206546#M60135</link>
      <description>&lt;P&gt;It returns no errors but it doesn't work.&lt;BR /&gt;
this regex is ok:&lt;BR /&gt;
&lt;CODE&gt;(?P\w+)\s\=\s\'\w+\s\w+\s\w+\'\sAND\s(?P\w+)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;and here is a piece of sample data:&lt;BR /&gt;
"existing_field": "class = 'Servizio...' AND category = 'Materiale...' AND ( ticket_type = 'Change Request' and ticket_impact_code = '2' ) AND ( ticket_type = 'Change Request' and ticket_urgency_code = '2' )"...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:10:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206546#M60135</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2020-09-29T07:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206547#M60136</link>
      <description>&lt;P&gt;You need to name the fields you are extracting (perhaps you did so and the editor dropped them).  What's more, the capturing groups need to be around the right side of the equals sign or all you will capture is the field name.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 18:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206547#M60136</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-09-07T18:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206548#M60137</link>
      <description>&lt;P&gt;This regex will work if the fields contain only word characters.  Try this as an alternative: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;class = '(?P&amp;lt;class&amp;gt;[^ ]+)' AND category = '(?P&amp;lt;category&amp;gt;[^ ]+)'
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 07 Sep 2015 18:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206548#M60137</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-09-07T18:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206549#M60138</link>
      <description>&lt;P&gt;I comfirm: the values are only word characters.&lt;/P&gt;

&lt;P&gt;I tried this but I get no new fields extracted:&lt;BR /&gt;
| rex field=sql_where_clause "class = '(?P[^ ]+)' AND category = '(?P[^ ]+)'"&lt;/P&gt;

&lt;P&gt;should I cancel the extraction row I added in relative sourcetype in the props.conf?&lt;/P&gt;

&lt;P&gt;Skender&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206549#M60138</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2020-09-29T07:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206550#M60139</link>
      <description>&lt;P&gt;sql_where_clause is the existing_field&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206550#M60139</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2020-09-29T07:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206551#M60140</link>
      <description>&lt;P&gt;And how about extracting entire strings (with white spaces included), not only words?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 10:51:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206551#M60140</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2015-09-08T10:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206552#M60141</link>
      <description>&lt;P&gt;here is some sample text:&lt;/P&gt;

&lt;P&gt;"existing_field: class = 'Service One...' AND category = 'Materials Two...' AND ( ticket_type = 'Change Request' and ticket_impact_code = '2' ) AND ( ticket_type = 'Change Request' and ticket_urgency_code = '2' )"...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206552#M60141</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2020-09-29T07:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206553#M60142</link>
      <description>&lt;P&gt;This regex extracts fields with spaces from your example.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;class = '(?P&amp;lt;class&amp;gt;.*?)' AND category = '(?P&amp;lt;category&amp;gt;.*?)'
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 08 Sep 2015 12:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206553#M60142</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-09-08T12:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I write the regex to extract fields from another existing field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206554#M60143</link>
      <description>&lt;P&gt;Thanks a lot:&lt;/P&gt;

&lt;P&gt;I resolved it this way:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=existing_field  "class = (?P.*?) AND category = (?P.*?) AND"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Skender&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 13:18:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-write-the-regex-to-extract-fields-from-another-existing/m-p/206554#M60143</guid>
      <dc:creator>skender27</dc:creator>
      <dc:date>2015-09-08T13:18:18Z</dc:date>
    </item>
  </channel>
</rss>

