All Apps and Add-ons

Need to compile a regex for a field

mmohiuddin
Path Finder

I have a field called STATUS that is displaying two values:

STATUS=In

STATUS=IN

I need to create a regex that would extract both the values and create a single field called Status.

Is there a way to do it?

There is an option [c|C] that can be used to ignore case sensitive phrases but I am unable to extract the right regex.

0 Karma

mmohiuddin
Path Finder

I was able to find a fix for my search.

We can use:

| eval STATUS = lower(STATUS) | ..

to merge both the upper case and lower case word results

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Having some sample events would help, but this should get you started. You can also go to www.regex101.com to test regex strings.

... | rex "STATUS=(?P<Status>\w+)" | ...
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...