All Apps and Add-ons

Extract version from event

hqw
Path Finder

Dear all,

I want to exact server version from the event, what i want is to extract 1.7.2, but my command can't show anything, could you pls kindly help?

event:
action="INFO:AppLoader (1.7.2 @143650)" category="System" label="(3a4c5025d457ef2e)" table="****"

AppLoader |rex field=_raw "action=\"(.:AppLoader (?<version> @.))" |stats latest(version) by table

0 Karma
1 Solution

aholzel
Communicator

The problem is probably the " after action= you need to either to escape that by putting a \ in front of it or remove it at all. You can use the below search to test.

AppLoader |rex field=_raw "action=.*?\((?<version>[^\s\@]+)" |stats latest(version) by table

View solution in original post

0 Karma

aholzel
Communicator

The problem is probably the " after action= you need to either to escape that by putting a \ in front of it or remove it at all. You can use the below search to test.

AppLoader |rex field=_raw "action=.*?\((?<version>[^\s\@]+)" |stats latest(version) by table
0 Karma

hqw
Path Finder

The last line is my current command

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...