Dashboards & Visualizations

Generating a table without fields

snobyink
Explorer

Greetings!

We are trying to generate a table after we got output from a Splunk query. We are trying pipe (|) this to our query but do not know how to do this. Can someone assist? 

This is the output after we ran our Splunk query,

Feb 13 20:36:21 hostname1 sshd[100607]: pam_unix(sshd:session): session opened for user user123 by (uid=0)

Feb 13 20:36:23 hostname2 sshd[100608]: pam_unix(sshd:session): session opened for user user345 by (uid=0)

We want to capture the table in this form,

Time                                   Hosts                       Users

Feb 13 20:36:21       hostname1                user123

Feb 13 20:36:23       hostname2                user345

And so on..

How do we do this. Thank you in advance!

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @snobyink,

in this case, please try this regex instead the previus one:

^\w+\s+\d+\s+\d+:\d+:\d+\s+(?<host>\w+).*user\s(?<user>\w+)+

that you can test at https://regex101.com/r/bV4B9h/1

Ciao.

Giuseppe

View solution in original post

snobyink
Explorer

Thank you for your help!

0 Karma

snobyink
Explorer

Thanks! Unfortunately the hostname is not extracted as a field. How do we extract host as well from the output? In the meantime we are looking to see if we can install this Add On if we can get past the red tape 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @snobyink,

in this case, please try this regex instead the previus one:

^\w+\s+\d+\s+\d+:\d+:\d+\s+(?<host>\w+).*user\s(?<user>\w+)+

that you can test at https://regex101.com/r/bV4B9h/1

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @snobyink,

at first, these seem to be Linux logs, so using the Splunk_TA_nix (https://splunkbase.splunk.com/app/833), you should have all the fields extracted.

Anyway, you can use a regex to extract the use field (the host should be already extracted:

index=your_index
| rex "for user (?<user>\w+)"
| table _time host user

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...