<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract data from a string that has variable length in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328554#M97794</link>
    <description>&lt;P&gt;I am fine with any approach as far as i get my result. &lt;/P&gt;

&lt;P&gt;regex as well is fine. &lt;/P&gt;</description>
    <pubDate>Thu, 19 Apr 2018 03:50:07 GMT</pubDate>
    <dc:creator>madakkas</dc:creator>
    <dc:date>2018-04-19T03:50:07Z</dc:date>
    <item>
      <title>Extract data from a string that has variable length</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328552#M97792</link>
      <description>&lt;P&gt;Hi I have the below data , and am trying to extract the below&lt;/P&gt;

&lt;P&gt;Start lsakjdf sdlkj sd CODE=CODE1 ksdjf ksajfd sakjdf&lt;BR /&gt;
Start $jdf$ ssfjdlkj sd CODE=CODE2 ksdjf ksajfd sakjdf&lt;BR /&gt;
Start lsakjdf CODE=CODE3 ksdjf ksajfd sakjdf&lt;BR /&gt;
Start lsakj44 sdlkj sdah sd CODE=CODE4 ksdjf ksajfd sakjdf&lt;/P&gt;

&lt;P&gt;CODE=CODE1&lt;BR /&gt;
CODE=CODE2&lt;BR /&gt;
CODE=CODE3&lt;BR /&gt;
CODE=CODE4&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 06:02:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328552#M97792</guid>
      <dc:creator>madakkas</dc:creator>
      <dc:date>2018-04-12T06:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from a string that has variable length</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328553#M97793</link>
      <description>&lt;P&gt;Are you looking for a regex? &lt;CODE&gt;(?P&amp;lt;data&amp;gt;\w+=\w+)&lt;/CODE&gt; maybe?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:21:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328553#M97793</guid>
      <dc:creator>damien_chillet</dc:creator>
      <dc:date>2018-04-12T12:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from a string that has variable length</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328554#M97794</link>
      <description>&lt;P&gt;I am fine with any approach as far as i get my result. &lt;/P&gt;

&lt;P&gt;regex as well is fine. &lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 03:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328554#M97794</guid>
      <dc:creator>madakkas</dc:creator>
      <dc:date>2018-04-19T03:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from a string that has variable length</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328555#M97795</link>
      <description>&lt;P&gt;Did you try below regex: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=_raw "(?P&amp;lt;data&amp;gt;\w+=\w+)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 Apr 2018 04:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328555#M97795</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-04-19T04:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from a string that has variable length</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328556#M97796</link>
      <description>&lt;P&gt;that did work , &lt;/P&gt;

&lt;P&gt;I set it up using the below as well &lt;/P&gt;

&lt;P&gt;|eval CODE = trim(substr(mvindex(split(MSGTXT," "),mvfind(split(MSGTXT," "),"CODE=")),0,10))&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2018 03:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-a-string-that-has-variable-length/m-p/328556#M97796</guid>
      <dc:creator>madakkas</dc:creator>
      <dc:date>2018-04-25T03:17:41Z</dc:date>
    </item>
  </channel>
</rss>

