<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extraction regular expression in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322622#M96318</link>
    <description>&lt;P&gt;I am using the extraction (regular expression) option to extract a particular field from the events.&lt;BR /&gt;
The issue I am having is the extraction works only for the previous events and not for the current ones coming in. Need some help.&lt;/P&gt;</description>
    <pubDate>Sat, 09 Sep 2017 00:15:42 GMT</pubDate>
    <dc:creator>bharpur183</dc:creator>
    <dc:date>2017-09-09T00:15:42Z</dc:date>
    <item>
      <title>Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322622#M96318</link>
      <description>&lt;P&gt;I am using the extraction (regular expression) option to extract a particular field from the events.&lt;BR /&gt;
The issue I am having is the extraction works only for the previous events and not for the current ones coming in. Need some help.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 00:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322622#M96318</guid>
      <dc:creator>bharpur183</dc:creator>
      <dc:date>2017-09-09T00:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322623#M96319</link>
      <description>&lt;P&gt;Field extractions are relative to the sourcetype. Are you sure that your using the correct sourcetype when looking at the new field?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 00:54:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322623#M96319</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-09-09T00:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322624#M96320</link>
      <description>&lt;P&gt;Where is the regular expression? config files, or auto field extractions, or SPL &lt;CODE&gt;rex&lt;/CODE&gt; in your search?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 01:15:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322624#M96320</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-09-09T01:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322625#M96321</link>
      <description>&lt;P&gt;So this is the actual event :&lt;/P&gt;

&lt;P&gt;9/8/17&lt;BR /&gt;
8:30:01.598 PM&lt;BR /&gt;&lt;BR /&gt;
2017-09-08T20:30:01.598-04:00 INFO m_gchgserv_gchg.cpp(2264)[9] GCHG::sendGchgUpdate() - 105971244 type: 1 note: In-Progress {FIFW GCHG 167015}: Install power supply&lt;BR /&gt;
  Scheduled            : 09/09/2017 00:30 GMT to 09/09/2017 03:30 GMT&lt;BR /&gt;
  Rep                  : Mike Sunil&lt;BR /&gt;
  Note: Install power supplies &lt;/P&gt;

&lt;P&gt;And from this I am trying to extract &lt;BR /&gt;
  Scheduled            : 09/09/2017 00:30 GMT to 09/09/2017 03:30 GMT&lt;/P&gt;

&lt;P&gt;This time window is different always depending on work.&lt;BR /&gt;
The extraction I did shows all the previous ones but not the current ones&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:38:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322625#M96321</guid>
      <dc:creator>bharpur183</dc:creator>
      <dc:date>2020-09-29T15:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322626#M96322</link>
      <description>&lt;P&gt;So this is the actual event :&lt;/P&gt;

&lt;P&gt;9/8/17&lt;BR /&gt;
8:30:01.598 PM&lt;BR /&gt;&lt;BR /&gt;
2017-09-08T20:30:01.598-04:00 INFO m_gchgserv_gchg.cpp(2264)[9] GCHG::sendGchgUpdate() - 105971244 type: 1 note: In-Progress {FIFW GCHG 167015}: Install power supply&lt;BR /&gt;
  Scheduled            : 09/09/2017 00:30 GMT to 09/09/2017 03:30 GMT&lt;BR /&gt;
  Rep                  : Mike Sunil&lt;BR /&gt;
  Note: Install power supplies &lt;/P&gt;

&lt;P&gt;And from this I am trying to extract &lt;BR /&gt;
  Scheduled            : 09/09/2017 00:30 GMT to 09/09/2017 03:30 GMT&lt;/P&gt;

&lt;P&gt;This time window is different always depending on work.&lt;BR /&gt;
The extraction I did shows all the previous ones but not the current ones&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322626#M96322</guid>
      <dc:creator>bharpur183</dc:creator>
      <dc:date>2020-09-29T15:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322627#M96323</link>
      <description>&lt;P&gt;Can you provide your regex?&lt;/P&gt;

&lt;P&gt;It should look something like this &lt;BR /&gt;
&lt;CODE&gt;(?&amp;lt;Field_Name&amp;gt;Scheduled.+)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 01:32:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322627#M96323</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-09-09T01:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322628#M96324</link>
      <description>&lt;P&gt;Am using the option " Extract new fields " from the left hand side column . The automatic option and no regex command line &lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 01:43:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322628#M96324</guid>
      <dc:creator>bharpur183</dc:creator>
      <dc:date>2017-09-09T01:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322629#M96325</link>
      <description>&lt;P&gt;Try appending this to the end of your search and see if it created the field &lt;CODE&gt;Field_Name&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| rex (?&amp;lt;Field_Name&amp;gt;Scheduled.+)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 01:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322629#M96325</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-09-09T01:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322630#M96326</link>
      <description>&lt;P&gt;It didn't do anything &lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 01:49:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322630#M96326</guid>
      <dc:creator>bharpur183</dc:creator>
      <dc:date>2017-09-09T01:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322631#M96327</link>
      <description>&lt;P&gt;Hi  bharpur183,&lt;BR /&gt;
Try with this regex in rex command or in field extraction:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "Scheduled\s+:\s+(?&amp;lt;Field_Name&amp;gt;.+)\s+Rep"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;test it at &lt;A href="https://regex101.com/r/o09dVs/1"&gt;https://regex101.com/r/o09dVs/1&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 06:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322631#M96327</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-09T06:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322632#M96328</link>
      <description>&lt;P&gt;This is a long shot: are you talking about an &lt;CODE&gt;accelerated datamodel&lt;/CODE&gt;?  When you accelerate a datamodel, it goes through an additional indexing pass that creates index-time fields and it is cooked into the tsidx &lt;CODE&gt;as it is now&lt;/CODE&gt;.  If you change the field extraction, then anything that is cooked after the change will reflect the change but not the stuff already cooked.  You can delete your datamodel acceleration and rebuild it.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 14:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322632#M96328</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-09-09T14:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322633#M96329</link>
      <description>&lt;P&gt;Try making it &lt;CODE&gt;multiline&lt;/CODE&gt; like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex "(?ms)[\r\n]+(?&amp;lt;Field_Name&amp;gt;Scheduled[^\r\n]+)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 09 Sep 2017 14:53:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322633#M96329</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-09-09T14:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Extraction regular expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322634#M96330</link>
      <description>&lt;P&gt;That worked. thanks cusello &lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 20:34:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extraction-regular-expression/m-p/322634#M96330</guid>
      <dc:creator>bharpur183</dc:creator>
      <dc:date>2017-09-09T20:34:37Z</dc:date>
    </item>
  </channel>
</rss>

