Getting Data In

Need help on Rex Please: How to extract the below events?

kc_prane
Path Finder

Hi, I need  to extract the below events i tried this  | rex "URI\s(?<URI>.+?)="   but not working. i want to extract for the 1& 2 events before the "="

URI /api/Hellothisistest?customerNumber=244479
URI /api/Hellothisistest?customerNumber=247370
URI  /api/Getthisextractessample
URI  /api/createthisextractesof
URI  /api/liverpooltestsoccer

 

Thanks in Advance

 

Labels (1)
Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

kc_prane
Path Finder

Thanks @gcusello  modifed your query and helped  | rex "URI\s*(?<URI>[^\=\n]+)"  worked for me

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

gcusello
SplunkTrust
SplunkTrust

Hi @kc_prane,

you can use this if you want to take all after URI:

 

| rex "URI\s*(?<URI>.+)=*"

 

if instead you want the URL until "=" when present, you can use the following regex:

 

| rex "URI\s*(?<URI>[^\=\n]+)(=*)|\n"

 

you can test this regex at https://regex101.com/r/jZY2kz/1

ciao.

Giuseppe

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...