Knowledge Management

How to use regex to get only the data cd?

shreyasamin64
Explorer

Regex to get only the data cd

ab.aaaa.asd.cd

Labels (1)
0 Karma

venky1544
Builder

HI @shreyasamin64 

you can try the below regex

| makeresults |eval new = "ab.aaaa.asd.cd" |rex field=new "(?<final>[\w+.].$)"|table _time,new ,final

 

venky1544_0-1650985397500.png

 

if it helps karma points are appreciated/please accept the solution if it worked 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "(\w+\.){3}(?<cd>\w+)"
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

&#x1f342; Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...