Archive
Highlighted

How to extract the status values from the following events?

Engager

Hi Team,

I have following two events from where i need to extract the status

)V 2019-03-11 msp raw utilityextract13L hdfs:/datalake/consumer/msp/raw/tmp/MSPDELTAPR936UTILITYEXTRACT13190311" consumermspraw.utilityextract13 utilityextract13DELTA9362019-03-12 06:10:21.9803272019-03-12 06:26:09.014586: warning - 35% data volume threshold reached, expected 2000

)V 2019-03-11 msp raw utilityextract13L hdfs:/datalake/consumer/msp/raw/tmp/MSPDELTAPR936UTILITYEXTRACT13190311" consumermspraw.utilityextract13 utilityextract13DELTA9362019-03-12 06:10:21.9803272019-03-12 06:26:09.014586 success

I need to extract the two highlighted status values into single filed, can you please help here. Thank you

@jkat54 @vnravikumar

0 Karma
Highlighted

Re: How to extract the status values from the following events?

SplunkTrust
SplunkTrust
0 Karma
Highlighted

Re: How to extract the status values from the following events?

Champion

Hi @pench2k19

Try this rex

|rex field=msg "\.\d+(:\s+|\s+)(?P<status>.+)"
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.