Getting Data In

Need help on Rex Please: How to extract the below events?

kc_prane
Communicator

Hi, I need  to extract the below events i tried this  | rex "URI\s(?<URI>.+?)="   but not working. i want to extract for the 1& 2 events before the "="

URI /api/Hellothisistest?customerNumber=244479
URI /api/Hellothisistest?customerNumber=247370
URI  /api/Getthisextractessample
URI  /api/createthisextractesof
URI  /api/liverpooltestsoccer

 

Thanks in Advance

 

Labels (1)
Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

kc_prane
Communicator

Thanks @gcusello  modifed your query and helped  | rex "URI\s*(?<URI>[^\=\n]+)"  worked for me

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

you can use this if you want to take all after URI:

 

| rex "URI\s*(?<URI>.+)=*"

 

if instead you want the URL until "=" when present, you can use the following regex:

 

| rex "URI\s*(?<URI>[^\=\n]+)(=*)|\n"

 

you can test this regex at https://regex101.com/r/jZY2kz/1

ciao.

Giuseppe

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...