Getting Data In

Getting A Specific Field From a Log

luteixeira
Explorer

Hello Splunkers. 🙂

I have a stream of logs going to Splunk that reports daily errors. The logs is as follows:

 

Exceptions Details
App...............: WebApp
Original Message..: The provided anti-forgery token was meant for user "1234" but the current user is "".
Server............: WebAppServer
Service API URL...: https://xpto.systemname.com/WebAppApi/SelfService/FI.API.SelfService

 

I have these kinds of exceptions going on through the day and night and my main goal is to compile the type of exception, which URL happened, where (server name) and how many times it happened.

So what I need is to extract the field after the : 

I've tried...

 

index="MyIndex" | extract kvdelim=":", auto=f

 

... as suggested in this cheat sheet but I couldn't manage to work.

Any help/suggestions? 🙂

Thank you in advance.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex max_match=0 "(?<key>[^\.:\n]+).*:\s(?<value>[^\n]*)"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex max_match=0 "(?<key>[^\.:\n]+).*:\s(?<value>[^\n]*)"
0 Karma

luteixeira
Explorer

@ITWhisperer You're awesome! 

Worked just fine for what I was looking for.

Thank you very much!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...