All Apps and Add-ons

help with field extraction

chauble
Engager

I have a log with the following types of entries.. I would like to extract the information between the single quotes into a field.. any insight would be appreciated

WARN The filing operation with containment name 'Missed Payment Second Letter Xen418' is experiencing high numbers of uniqueness violations

WARN The filing operation with containment name 'Changing Your Child Support Order Xen261' is experiencing high numbers of uniqueness violations

WARN The filing operation with containment name 'Transfer Letter, Universal Xenn351A-B, Xen351SPA, Xen351SOM' is experiencing high numbers of uniqueness violations

1 Solution

carasso
Splunk Employee
Splunk Employee

use rex or make a saved field extraction. this regex extracts anything between two single quotes...

... | rex "'(?<my_quoted_field>[^']*)'"

View solution in original post

carasso
Splunk Employee
Splunk Employee

use rex or make a saved field extraction. this regex extracts anything between two single quotes...

... | rex "'(?<my_quoted_field>[^']*)'"
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...