All Apps and Add-ons

help with field extraction

Engager

I have a log with the following types of entries.. I would like to extract the information between the single quotes into a field.. any insight would be appreciated

WARN The filing operation with containment name 'Missed Payment Second Letter Xen418' is experiencing high numbers of uniqueness violations

WARN The filing operation with containment name 'Changing Your Child Support Order Xen261' is experiencing high numbers of uniqueness violations

WARN The filing operation with containment name 'Transfer Letter, Universal Xenn351A-B, Xen351SPA, Xen351SOM' is experiencing high numbers of uniqueness violations

1 Solution

Splunk Employee
Splunk Employee

use rex or make a saved field extraction. this regex extracts anything between two single quotes...

... | rex "'(?<my_quoted_field>[^']*)'"

View solution in original post

Splunk Employee
Splunk Employee

use rex or make a saved field extraction. this regex extracts anything between two single quotes...

... | rex "'(?<my_quoted_field>[^']*)'"

View solution in original post

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!