Splunk Enterprise

How to build rex for field extraction in one event?

kc_prane
Path Finder

Hello,  Can someone  Please help to build rex for field extraction in one event. Currently iam using the below basic rex but its pulling only first line in the results. i need all the results so i can table them.

|rex field=_raw "(TEST_DETAIL_MESSAGE\s\=)(?<MESSAGE>\w+\D+\,)" |rex field=_raw "(TEST_COUNT\s\=)(?<COUNT>\s\d+)"

 

kc_prane_1-1659490249672.png

Labels (1)
Tags (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
0 Karma

kc_prane
Path Finder

Thanks @isoutamo

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...