Alerting

How to write regular expression for the below log and to extract error code, message and status code?

vineela
Path Finder

i need to write regular expression for the below log and i need to extract error code,message and status code:

{"log":"28/Oct/2022:22:23:39 +1100 [qtp2012846597-33] [correlationId=00223854-356e-4a24-bc04-4bce27407dfa] ERROR au.com.commbank.pso.payments.reportgen.util.LoggingUtil - Severity = \"ERROR\", DateTimestamp = \"28/Oct/2022 22:23:39\", Error Code = \"REPORT_GENERATION_ERR_0007\", Error Message = \"API call to IDP failed with HTTP Status Code 4XX\", HTTP Status Code = \"500\"

 

 

Thanks in Advance

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex "Error Code = \\\\\"(?<errorCode>[^\\\\]+)"
| rex "Error Message = \\\\\"(?<errorMessage>[^\\\\]+)"
| rex "HTTP Status Code = \\\\\"(?<HTTPStatusCode>[^\\\\]+)"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "Error Code = \\\\\"(?<errorCode>[^\\\\]+)"
| rex "Error Message = \\\\\"(?<errorMessage>[^\\\\]+)"
| rex "HTTP Status Code = \\\\\"(?<HTTPStatusCode>[^\\\\]+)"
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...