I would like to extract status value (i.e. 201) highlighted below using RegEx in the following link. However, it didn't work. Please advise
https://regex101.com/r/QIB8EG/1
Rex \"status\":(?<status>[^\}])\",\"requestId\":
{"level":"debug","message":"handler result : {\"body\":\"{\\\"numberOfProcessedRecords\\\":1}\",\"status\":201}","requestId":"ecd06f97-975b-5faf-81a0-3431fb4d1070"}
Hi @Manth,
please try this:
\"status\\\":(?<status>\d+)that you can test at https://regex101.com/r/QIB8EG/2
Ciao.
Giuseppe
Hi @Manth,
please try this:
\"status\\\":(?<status>\d+)that you can test at https://regex101.com/r/QIB8EG/2
Ciao.
Giuseppe
Thank you @gcusello .
When I have my splunk query as below, I was expecting Status in the SELECTED FIELDS, however, I don't see the Status filed in the left menu. Am I doing anything wrong here. Please advise.
index=application source="aws:lambda" | rex "\\"status\\":(?<Status>\w+)}\""
Hi @Manth,
if you create a field using rex, by default you have this field in interesting fields not in Selected fields.
If you want it in Selected fields, you have to select it!
Ciao.
Giuseppe
Thank you @gcusello
Hi @Manth,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉