Dashboards & Visualizations

EXTRACTION

sphiwee
Contributor

trying to extract using this regular expression below 


rex field=_raw "name\=\w+\s+(?<business_field>.*)"

I'm struggling to extract the from below text, i want to extract the bold part

Capabilities [{capabilityNodeId=http://127.0.0.1:5000, extra.executor.id={run.name= [FraudLogsCard] ATMX Logs Request/Extraction/Attach 2.1.3, task.uuid=c9999999-9999-49999-9999-99999999,

 

 

 

 

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
rex field=_raw "name\=\s+(?<business_field>[^,]+)"
0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...