Reporting

Regex - Cannot extract terms with spaces

POR160893
Builder

Hi,

I am using the following rex command to extract all text in between "....device-group:" and "succeeded ...." for a field called "old" and assigning the extracting values to a new field called "new".

| rex field=old "device-group:\s*(?<new>\S+)"

Currently, it is extracting all text in between "....device-group:" and "succeeded ...." EXCEPT for cases where there are multiple words with spaces.

Examples include:

1) "Panorama push to device:013101009509 for device-group: Austin Cloud DMZ succeeded. JobId=2484595" where the extracted values should be "Austin Cloud DMZ "

2) "Panorama push to device:013101014290 for device-group: Austin Bank Segmentation succeeded. JobId=2482583" where the extracted values should be "Austin Bank Segmentation"


Can you please help on extracting  such cases too?

Thank you!

Labels (1)
0 Karma
1 Solution

POR160893
Builder

Solved it myself actually: | rex field=body "device-group:\s*(?<deviceGroup>.+?) succeeded"

View solution in original post

0 Karma

POR160893
Builder

Solved it myself actually: | rex field=body "device-group:\s*(?<deviceGroup>.+?) succeeded"

0 Karma
Get Updates on the Splunk Community!

Celebrating the Winners of the ‘Splunk Build-a-thon’ Hackathon!

We are thrilled to announce the winners of the Splunk Build-a-thon, our first-ever hackathon dedicated to ...

Why You Should Register for Splunk University at .conf25

Level up before .conf25 even begins Splunk University is back in Boston, September 6–8, and it’s your chance ...

Building Splunk proficiency is a marathon, not a sprint

Building Splunk skills is a lot like training for a marathon. It’s about consistent progress, celebrating ...