<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to fetch data using rex command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331604#M98641</link>
    <description>&lt;P&gt;It looks like you are trying to extract all the values, but eliminate any values that have numbers or ampersands in them.  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=_raw "name\&amp;gt;(?&amp;lt;CoreOffering&amp;gt;[^\&amp;lt;]+)" max_match=50
| eval CoreOffering = mvfilter(NOT match(CoreOffering,"[&amp;amp;0-9]"))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, "Strong kham Minor and Major Core" is an exception. Did you want to get rid of that? &lt;/P&gt;

&lt;P&gt;Use this at the end if six words (with spaces between them) is enough to disqualify a result...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval CoreOffering = mvfilter(NOT match(CoreOffering,"\S+\s+\S+\s+\S+\s+\S+\s+\S+\s+\S"))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Use this at the end if the word " and " is enough to disqualify a result...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval CoreOffering = mvfilter(NOT match(CoreOffering,"\s+and\s+"))
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 09 Jun 2017 18:12:54 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2017-06-09T18:12:54Z</dc:date>
    <item>
      <title>How to fetch data using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331600#M98637</link>
      <description>&lt;P&gt;These are some below mentioned details which is present in splunk in exactly same format:-&lt;BR /&gt;
New Core 12 Month CTE (2014)(HEROCN2 &amp;amp; HEROTV2)&lt;BR /&gt;
Mix Core&lt;BR /&gt;
Full House Core&lt;BR /&gt;
Player Core&lt;BR /&gt;
Fun Core&lt;BR /&gt;
35% off Mix Core 12m (11887)&lt;BR /&gt;
Full House Minor Core&lt;BR /&gt;
Fun bundle&lt;BR /&gt;
Full House Minor &amp;amp; Major Core&lt;BR /&gt;
Full House Major Core&lt;BR /&gt;
VIP Core&lt;BR /&gt;
Strong kham Core&lt;BR /&gt;
Strong Easy Core&lt;BR /&gt;
Strong kham Minor Core&lt;BR /&gt;
Strong Bang Core&lt;BR /&gt;
3 for ??44 Triple Core&lt;BR /&gt;
Strong kham Minor and Major Core&lt;BR /&gt;
ATL Player Core (50mb &amp;amp; above) 12m discount 12m CTE (11957)&lt;BR /&gt;
ACQ Strong kham Core TVXL/BBXXL/Phone M Triple with TiVo, 12 month offer (11768)&lt;BR /&gt;
35% off Full House Core 12m (11888)&lt;/P&gt;

&lt;P&gt;I wanted to fetch only these below mentioned names using rex command:-&lt;/P&gt;

&lt;P&gt;Mix Core&lt;BR /&gt;
Full House Core&lt;BR /&gt;
Player Core&lt;BR /&gt;
Fun Core&lt;BR /&gt;
Full House Minor Core&lt;BR /&gt;
Full House Major Core&lt;BR /&gt;
VIP Core&lt;BR /&gt;
Strong kham Core&lt;BR /&gt;
Strong Easy Core&lt;BR /&gt;
Strong kham Minor Core&lt;BR /&gt;
Strong Bang Core&lt;/P&gt;

&lt;P&gt;Could you please help me in creating the rex command which will only provide me the above mentioned details as a result.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 14:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331600#M98637</guid>
      <dc:creator>m7787580</dc:creator>
      <dc:date>2017-06-09T14:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch data using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331601#M98638</link>
      <description>&lt;P&gt;Are these a field values available in multiple events and you want to filter to keep only the events with field in format specified in your second list? What's your current search?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 16:24:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331601#M98638</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-06-09T16:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch data using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331602#M98639</link>
      <description>&lt;P&gt;Yes these fields are present in multiple events i just want to rex out above mentioned fields from them.&lt;/P&gt;

&lt;P&gt;I tried to use below mentioned search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rex field=_raw "name\&amp;gt;(?&amp;lt;CoreOffering&amp;gt;[^\&amp;lt;]+)" max_match=50|top CoreOffering limit=0|search CoreOffering =*Core*|rex field=CoreOffering "(?\w*\s*[^\C]+)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But is not extracting the exact field name which i want.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 16:36:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331602#M98639</guid>
      <dc:creator>m7787580</dc:creator>
      <dc:date>2017-06-09T16:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch data using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331603#M98640</link>
      <description>&lt;P&gt;How about this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; |rex field=_raw "name\&amp;gt;(?&amp;lt;CoreOffering&amp;gt;[^\&amp;lt;]+)" max_match=50|top CoreOffering limit=0|search CoreOffering =*Core*|rex field=CoreOffering "^(?&amp;lt;FilteredCoreOffering&amp;gt;[A-z\s]+)$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 09 Jun 2017 16:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331603#M98640</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-06-09T16:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch data using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331604#M98641</link>
      <description>&lt;P&gt;It looks like you are trying to extract all the values, but eliminate any values that have numbers or ampersands in them.  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=_raw "name\&amp;gt;(?&amp;lt;CoreOffering&amp;gt;[^\&amp;lt;]+)" max_match=50
| eval CoreOffering = mvfilter(NOT match(CoreOffering,"[&amp;amp;0-9]"))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, "Strong kham Minor and Major Core" is an exception. Did you want to get rid of that? &lt;/P&gt;

&lt;P&gt;Use this at the end if six words (with spaces between them) is enough to disqualify a result...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval CoreOffering = mvfilter(NOT match(CoreOffering,"\S+\s+\S+\s+\S+\s+\S+\s+\S+\s+\S"))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Use this at the end if the word " and " is enough to disqualify a result...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval CoreOffering = mvfilter(NOT match(CoreOffering,"\s+and\s+"))
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 09 Jun 2017 18:12:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331604#M98641</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-06-09T18:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch data using rex command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331605#M98642</link>
      <description>&lt;P&gt;@m7787580 - did you ever get a solution to this?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 14:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fetch-data-using-rex-command/m-p/331605#M98642</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-08-11T14:41:35Z</dc:date>
    </item>
  </channel>
</rss>

