Hi Support,
Can you please help me for field extraction id reference number and formid
{"id":"0fb56c6a-39a6-402b-8f07-8b889a46e3e8","referenceNumber":"UOB-SG-20240101-452137857","formId":"sg-pfs-save-savings-festival"}
Thanks,
Hari
For such events, if they are in valid JSON format, Splunk may automatically extract the fields.
If not, you could also try the field extraction wizard in Splunk, which should be able to generate a working regex for you if you select the fields you want.
If not, this one may work for your purpose, but it assumes that there are no empty fields:
id":"(?<id>[^"]*)","referenceNumber":"(?<referenceNumber>[^"]*)","formId":"(?<formId>[^"]*)"