Monitoring Splunk

create alert

vineela
Path Finder

Hi All,

    I have logs in splunk and i need to create field values and create table with the values,present in logs.

example :Caused by: org.apache.kafka.connect.errors.ConnectException: Failed to start new JMS session connection 1: JMSWMQ2013: The security authentication was not valid that was supplied for queue manager 'EVT302' with connection mode 'Client' and host name '10.37.84.12,10.37.100.13(1442)'.

Above one is the example log and i need to extract value under caused by as description and queue manager number and also the hostname. 
Can anyone help me on the same.

Thanks in Advance.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "Caused by: (?<cause>([^:]+:){3}).*queue manager '(?<queuemanager>[^']+).*host name '(?<hostname>[^']+)"
0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...