Security

Multiple spaces in between data

hazarath
New Member

2018-07-28 12:55:48 ET GOT /itune/odb/1234567/sms/unread/count?_=123456 200 A1D2F3G45H6HY6@AK C1FV2G32G3HH34H+mP4yT+12gc= 10.131.42.16 0.013

Hi This is my sample dynamic data , we have to create raw fields and create a table with the following fields...URI,STATUS CODE, REQID, SESSIONID

Can anyone help me the query with the following fields

Tags (1)
0 Karma

sbbadri
Motivator

| rex field=_raw "(?P<date>\d+-\d+-\d+\s\d+:\d+:\d+)\s\S+\s\S+\s(?P<URI>\S+)\s(?P<status>\d+)\s(?P<code>\S+.*)\s(?P<REQID>\d+.\d+.\d+.\d+)\s(?P<SESSIONID>\d+.\d+)"

0 Karma

hazarath
New Member

Thank you for your reply. Its not working for me, looks like i am not explain teh question to you properly. I will share more details.

0 Karma

sbbadri
Motivator

sure. In between i had a typo in the query. Please check again

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...