<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to write a regular expression to extract this 3 digit number from my sample events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264020#M79239</link>
    <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "\s(?&amp;lt;status&amp;gt;\d\d\d)\s" | table status
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 01 Sep 2016 16:56:54 GMT</pubDate>
    <dc:creator>sundareshr</dc:creator>
    <dc:date>2016-09-01T16:56:54Z</dc:date>
    <item>
      <title>How to write a regular expression to extract this 3 digit number from my sample events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264019#M79238</link>
      <description>&lt;P&gt;I have these statements I am trying to extract the "200" from, but this number could be any three digit number though.&lt;/P&gt;

&lt;P&gt;&amp;lt;117&amp;gt;Sep 01 16:19:12 ip-10-255-55-21 SLAVE[prodr35e-core_24322]: 10-255-55-21 10-255-55-21 - 2016-09-01 16:19:12 86 GET /search?keyword=true&amp;amp;sortKey=4&amp;amp;start=2100&amp;amp;count=s=false&amp;amp;marketPlace=true HTTP/1.1 ?keyword=true&amp;amp;sortKey=4&amp;amp;start=2100&amp;amp;count=60&amp;amp;s=false&amp;amp;marketPlace=true &lt;STRONG&gt;200&lt;/STRONG&gt; 33687 "Jak Commons-HttpClient/3.1"&lt;/P&gt;

&lt;P&gt;&amp;lt;117&amp;gt;Sep 01 16:19:12 ip-10-444-33-63 SLAVE[prodr35e-core_390959]: 10-444-33-634 10-444-33-65 - 2016-09-01 16:19:12 2 GET /index.html HTTP/1.0  &lt;STRONG&gt;200&lt;/STRONG&gt; 1488 "-"&lt;/P&gt;

&lt;P&gt;&amp;lt;117&amp;gt;Sep 01 16:19:12 ip-10-999-39-99 SLAVE[prodr35e-core_390959]: 10.999.39.79 10.999.39.99 - 2016-09-01 16:19:12 252 GET /search?keyword=true&amp;amp;count=0&amp;amp;sendRefinements=false&amp;amp;marketPlace=true&amp;amp;isBOPUS=true&amp;amp;storeId=555&amp;amp;storeId=592&amp;amp;storeId=696&amp;amp;storeId=548&amp;amp;storeId=592 HTTP/1.1 ?keyword=true&amp;amp;count=0&amp;amp;sendRefinements=false&amp;amp;marketPlace=true&amp;amp;isBOPUS=true&amp;amp;storeId=555&amp;amp;storeId=592&amp;amp;storeId=696&amp;amp;storeId=548&amp;amp;storeId=592 &lt;STRONG&gt;200&lt;/STRONG&gt; 973 "Jak Commons-HttpClient/3.1"&lt;/P&gt;

&lt;P&gt;&amp;lt;117&amp;gt;Sep 01 16:19:12 ip-10-200-00-00 SLAVE[prodr35e-core_489352]: 127.0.0.1 10.200.00.00 - 2016-09-01 16:19:12 0 GET /products/admin/beans?key=/select&amp;amp;stats=true&amp;amp;cat=QUERYHANDLER&amp;amp;wt=json HTTP/1.1 ?key=/select&amp;amp;stats=true&amp;amp;cat=QUERYHANDLER&amp;amp;wt=json &lt;STRONG&gt;200&lt;/STRONG&gt; 733 "Python-urllib/2.7"&lt;/P&gt;

&lt;P&gt;&amp;lt;117&amp;gt;Sep 01 16:19:12 ip-10-204-38-110 SLAVE[prodr35e-core_497105]: 10.222.22.22 10.222.22.222 - 2016-09-01 16:19:12 41 GET /search?&amp;amp;count=96&amp;amp;start=0&amp;amp;ltl=false HTTP/1.1 ?count=96&amp;amp;start=0&amp;amp;ltl=false &lt;STRONG&gt;200&lt;/STRONG&gt; 6903 "Java/1.7.0_55"&lt;/P&gt;

&lt;P&gt;I just can't seem to get my regex to work for all of these statements, help would be highly appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264019#M79238</guid>
      <dc:creator>JoshuaJohn</dc:creator>
      <dc:date>2020-09-29T10:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression to extract this 3 digit number from my sample events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264020#M79239</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "\s(?&amp;lt;status&amp;gt;\d\d\d)\s" | table status
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Sep 2016 16:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264020#M79239</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-09-01T16:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression to extract this 3 digit number from my sample events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264021#M79240</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;your search | rex field=_raw "\s(?&amp;lt;response&amp;gt;\d\d\d[^\s])" | table response
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Sep 2016 17:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264021#M79240</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2016-09-01T17:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression to extract this 3 digit number from my sample events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264022#M79241</link>
      <description>&lt;P&gt;regex might not be what you want to use, You have several 3 digit numbers, however it seems like the data is all of a uniform format with spaces between fields. Using split you could do&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;eval temp=split(_raw," ") | eval status=mvindex(temp,15) | fields - temp
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Sep 2016 19:01:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-to-extract-this-3-digit-number/m-p/264022#M79241</guid>
      <dc:creator>vanderhoff</dc:creator>
      <dc:date>2016-09-01T19:01:44Z</dc:date>
    </item>
  </channel>
</rss>

