<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract all fields between a word and two specific characters in a string? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259566#M77804</link>
    <description>&lt;P&gt;Thanks you.&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2016 07:16:21 GMT</pubDate>
    <dc:creator>royimad</dc:creator>
    <dc:date>2016-05-31T07:16:21Z</dc:date>
    <item>
      <title>How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259558#M77796</link>
      <description>&lt;P&gt;I have a text as following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Hello OFF anything blah blah &amp;amp; ^ anything -   )&amp;lt;  OFF anything blo blo &amp;amp; ^ ble -  )&amp;lt; OFF  anything bli bli &amp;amp; ^ ble -  )&amp;lt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I need to extract all the fields that start with &lt;CODE&gt;OFF&lt;/CODE&gt; and end with 2 characters &lt;CODE&gt;)&amp;lt;&lt;/CODE&gt;&lt;BR /&gt;
In my case, 3 fields need to be extracted.&lt;/P&gt;

&lt;P&gt;I wrote a search, but it's only extracting the first occurrence while I want to extract all the fields&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; sourcetype=imap OFF | rex field=_raw "OFF (?&amp;lt;myfields&amp;gt;.*?)\)\&amp;lt;"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 May 2016 12:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259558#M77796</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2016-05-20T12:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259559#M77797</link>
      <description>&lt;P&gt;How about this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  rex "(?ms)(?&amp;lt;=OFF )(?&amp;lt;myFields&amp;gt;.*)(?=\)\&amp;gt;)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If that doesn't work, try it without (?ms).&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 12:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259559#M77797</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-20T12:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259560#M77798</link>
      <description>&lt;P&gt;You might also have to break the source data into one event per line.&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 12:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259560#M77798</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-20T12:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259561#M77799</link>
      <description>&lt;P&gt;Your regular expression select the field started by OFF and ended with )&amp;lt; into one field but it did not split it into 3 fields , i can't break the source data into one event per line ( its an email while i'm trying to decode )&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 12:35:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259561#M77799</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2016-05-20T12:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259562#M77800</link>
      <description>&lt;P&gt;I also try it without ms ( the result is the same, one field was selected as following:&lt;BR /&gt;
Field started with the first concurrence of OFF and ending with the last occurrence of )&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 12:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259562#M77800</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2016-05-20T12:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259563#M77801</link>
      <description>&lt;P&gt;Did it split the desired fields by spaces but into just one field?&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 13:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259563#M77801</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-20T13:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259564#M77802</link>
      <description>&lt;P&gt;This should work (use only  the rex command segment)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| gentimes start=-1 | eval _raw="Hello OFF anything blah blah &amp;amp; ^ anything - )&amp;lt; OFF anything blo blo &amp;amp; ^ ble - )&amp;lt; OFF anything bli bli &amp;amp; ^ ble - )&amp;lt;" | rex max_match=0 field=_raw "OFF\s(?&amp;lt;field&amp;gt;[^\)]+)" | table field
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 May 2016 13:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259564#M77802</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-05-20T13:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259565#M77803</link>
      <description>&lt;P&gt;If so we can fix it from there.&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2016 13:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259565#M77803</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-20T13:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract all fields between a word and two specific characters in a string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259566#M77804</link>
      <description>&lt;P&gt;Thanks you.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 07:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-fields-between-a-word-and-two-specific/m-p/259566#M77804</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2016-05-31T07:16:21Z</dc:date>
    </item>
  </channel>
</rss>

