Security

extract username for element in path

kritho
Explorer

Hi,
Im new to regexes, and I'm trying to get the username field configuration to my extract-fields

source:
/u01/somedir/somedir/user1/anotherfile
/u01/somedir/somedir/user3/anotherfile2
/u01/somedir/somedir/user4/anotherfile3

I want to get the "user1|2|3" part to a username field.

Any tips?
brgds/K

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

To do that inline in the search, you can use rex in the example below, look at the fourth element of the path (i.e. source);

your search | rex field=source "/([^/]+/){3}(?<username>[^/]+)"

/K

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...