Splunk Search

Dynamic trim of field at both start and end

ramgnisiv
Path Finder

Hi, i have a field that i need to trim.
The field can have a number of different strings, for which i want to trim everything except 1 word.

The fields can look like this:

Deployment of ABC with version 3.0.348 to Acceptance
Deployment of Application XYZ with version : 1.8.540 to Production

I'm only interested in the ABC and XYZ part of these strings.

The part that says "Deployment of " or "Deployment of Application " at the start should be removed.
The part that says " with version ........" all the way to the end should be removed.

What would be the best way of doing this? I've been messing about with regex, trim, replace, without success.

Edit: The following regex appears to work when i try it in any regex editor online, but i cannot get this to work in splunk:

.*(?:Application)? ? (.*) with.*
0 Karma
1 Solution

rafadvega
Path Finder

Yo can try this:

| rex field=<yourfield> ("(Deployment of Application|Deployment of)\s(?<Application>.*)\swith version.*")

View solution in original post

rafadvega
Path Finder

Yo can try this:

| rex field=<yourfield> ("(Deployment of Application|Deployment of)\s(?<Application>.*)\swith version.*")

Sukisen1981
Champion

try this "Application\s+(?<application>.*?)\s+" max_match=0

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...