Splunk Enterprise Security

rex fields

lucky
Explorer

 

HI ,

please help to get new field URI by using rex 



/area/label/health/readiness||||||||||METRICS|--

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this should works

...
| rex "(?<URI>^[^\|]+)"

 I assume that your event is in _raw. If it's already in some field then just add "fields=<your field>" after rex.

https://regex101.com/r/IsMwQy/1

r. Ismo

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your question is rather vague, but assuming you want the beginning of the _raw event field up to but not including the first | you could try this

| rex "^(?<url>[^\|]+)"
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...