Splunk Search

Datas are not getting parsed after giving table name on splunk query.

Splunk-Star
Loves-to-Learn Lots

Please let me know the correct data extraction?

 

index=* "Unknown message for StatusConsumer" topicId marshall
| rex field=_raw "\"topicId\":\"(?<topicId>\d+)\""
| table topicId

 

Datas are not getting parsed after giving table name on splunk query.

Labels (3)
0 Karma

Splunk-Star
Loves-to-Learn Lots

regex was not applied correctly thats why it was not extracting the data.

 

Thank you

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Please post an example of your data containing topicid

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Splunk-Star,

After using table or stats commands Splunk shows only outputs of these commands. This does not mean they are not extracted. If you need to access other fields, add them to the table command. 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...