Deployment Architecture

regex help to split into two rows of data

thaghost99
Path Finder

here is the current data

 

Feb 27 14:12:38
node0:
--------------------------------------------------------------------------

Attack database version:3670(Thu Feb 22 14:12:38 2024 UTC)
Detector version :12.2.140230313
Policy template version :3535

node1:
--------------------------------------------------------------------------

Attack database version:3670(Thu Feb 22 14:12:38 2024 UTC)
Detector version :12.2.140230313
Policy template version :3535

{primary:node0}

 

 

i need help extracting the values for attack version (just the digit), detector version and policy template version, by node (ie: node 0 and node 1)

 

output looks like something like this

 

Node               Attack database version                 Detector version                Policy template version

node0             3670                                                         12.2.140230313               3535

node1             3670                                                         12.2.140230313               3535

 

 

please and thank you, i am only able to get the node0 but not node1 😞

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @thaghost99,

please try this regex:

| rex "(?ms)(?<node>node\d+).*?Attack database version:(?<Attack_database_version>\d+).*?Detector version\s*:(?<Detector_version>[^\n]+).*?Policy template version\s*:(?<Policy_template_version>\d+)"

that you can test at https://regex101.com/r/R9SWnM/1

Ciao.

Giuseppe

View solution in original post

thaghost99
Path Finder

thanks that did it. thank you

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @thaghost99,

please try this regex:

| rex "(?ms)(?<node>node\d+).*?Attack database version:(?<Attack_database_version>\d+).*?Detector version\s*:(?<Detector_version>[^\n]+).*?Policy template version\s*:(?<Policy_template_version>\d+)"

that you can test at https://regex101.com/r/R9SWnM/1

Ciao.

Giuseppe

Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...