Getting Data In

Parsing text

mfrederickson
New Member

I apologize in advance if this question has already been asked and answered. If it has, I am most likely demonstrating my lack of experience in not knowing what to properly search for. I am relatively new to regex. Here is my problem:

I have several records in my file that contain a three digit number (233, 252, 245, etc.) In the lines I am concerned about, they always appear between the ampersand:

& 232 &

& 252 &

So it's ampersand, space, three digit number, space and then ampersand.

How can I extract just the number from the string? I can't seem to find what I am looking for - I really do better with actual examples.....

Any assistance would be appreciated.....even if it's pointing me to documentation somewhere (I know RTFM...)

Thanks

Tags (1)
0 Karma

mfrederickson
New Member

Thanks Vince - I'll give that a shot. I knew it couldn't be that complicated - just having a major brain fart...

0 Karma

vincesesto
Communicator

Hey mfrederckson,

This should be pretty straight forward with a regex such as the following:
&\s(?P[^ ]+)\s&

If you could provide some more information on the actual logs you are searching through, as well as the context of your regex, eg; is it for a props.conf or a search, etc...I would be happy to assist further.

Regards Vince

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...