I have a field which contains various data, one of the data is the file hash. I would like to extract it to a field.
Tue Jul 15 09:32:03 CET 2019 app=testapp file_hash=aaaaaaaaaaaaaaaa1234567890123456 os=linux
I would like to extract the file_hash: 32 chars only letters and numbers.
Many thanks.
This should do it.
... | rex field=foo "file_hash=(?<file_hash>.{32})" | ...
Hi Gyr1991,
I can provide following regex
file_hash\=(?<EXTRACTION1>\w+)\s+
or just for the letters and numbers:
file_hash\=(?<EXTRACTION1>[[:alnum:]]+)\s+
You can use one of them in the fields-extractor of splunk.
Hope this helps 🙂
Kind Regards,
Michael