Knowledge Management

How to use regex to get only the data cd?

shreyasamin64
Explorer

Regex to get only the data cd

ab.aaaa.asd.cd

0 Karma

venky1544
Builder

HI @shreyasamin64 

you can try the below regex

| makeresults |eval new = "ab.aaaa.asd.cd" |rex field=new "(?<final>[\w+.].$)"|table _time,new ,final

 

venky1544_0-1650985397500.png

 

if it helps karma points are appreciated/please accept the solution if it worked 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "(\w+\.){3}(?<cd>\w+)"
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...