Splunk IT Service Intelligence

Hi Team, I need to extract the field program name from the logs .

Hemant1
Explorer

"program_name"=>"Love Lagna Locha - Episode 117 - January 31, 2017 - Full Episode"

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

One way is with rex.

... | rex "program_name\"=>\"(?<program_name>[^\"]+)\"" | ...
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

One way is with rex.

... | rex "program_name\"=>\"(?<program_name>[^\"]+)\"" | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma

Hemant1
Explorer

thank you so much

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...