All Apps and Add-ons

How to split one field into two using regex?

Italy1358
Path Finder

Hello, I am working on a Splunk query and I need help adjusting my rex command to get two fields that are in one field into their own fields. Example below:
index=test sourcetype=test category=test
| rex field=user "(?<region>[^\/]+)\/(?<username>[^\w].+)"
| fillnull t
| sort _time
| table _time, username, user, region, sourcetype,  result, t
| bin span=1d _time
| dedup t

The user field has: test\test1 and I need it to split that so username=test region=test1

Labels (1)
Tags (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Italy1358,

if the format of your user field is "test\test1", your regex is wrong, please try this:

| rex field=user "^(?<region>[^\\]+)\\(?<username>.+)"

that you can test at https://regex101.com/r/eLZV41/1

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Italy1358,

if the format of your user field is "test\test1", your regex is wrong, please try this:

| rex field=user "^(?<region>[^\\]+)\\(?<username>.+)"

that you can test at https://regex101.com/r/eLZV41/1

Ciao.

Giuseppe

Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...