Getting Data In

Need help on Rex Please: How to extract the below events?

kc_prane
Path Finder

Hi, I need  to extract the below events i tried this  | rex "URI\s(?<URI>.+?)="   but not working. i want to extract for the 1& 2 events before the "="

URI /api/Hellothisistest?customerNumber=244479
URI /api/Hellothisistest?customerNumber=247370
URI  /api/Getthisextractessample
URI  /api/createthisextractesof
URI  /api/liverpooltestsoccer

 

Thanks in Advance

 

Labels (1)
Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

kc_prane
Path Finder

Thanks @gcusello  modifed your query and helped  | rex "URI\s*(?<URI>[^\=\n]+)"  worked for me

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

you can use this if you want to take all after URI:

 

| rex "URI\s*(?<URI>.+)=*"

 

if instead you want the URL until "=" when present, you can use the following regex:

 

| rex "URI\s*(?<URI>[^\=\n]+)(=*)|\n"

 

you can test this regex at https://regex101.com/r/jZY2kz/1

ciao.

Giuseppe

Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...