Splunk Search

Extract a string from a field using regex.

NicoloPunzalan2
Engager

Hi All,

I am having an issue on extracting a string in a field. For example, I have this data below:

"18/10/2018 03:44:35 - Joneil Englis (Additional comments) Hi All, this is now being investigated. We'll keep you updated on our progress. 16/10/2018 04:40:51 - David Jinn Hong Chia (Additional comments) Hi team Another Shipment Cost Document has the same issue in E1P today. 563638 15/10/2018 02:21:06 - Christian Espinosa (Additional comments) Hi All, this is now being investigated. We'll keep you updated on our progress. "

I need to get the latest name on who updated the ticket. I am trying to use a regex expression where i can get the string between the character "-" and "(" but sometimes the data of the field contains many occurrence of these characters.

I need to get the string Joneil Englis. Could anyone help me?

Thanks in advance.

0 Karma
1 Solution

FrankVl
Ultra Champion

If the latest occurrence is always at the start, it is fairly straightforward:

^"\d+\/\d+\/\d+\s+\d+:\d+:\d+\s+-\s+(?<name>[^\(]+)\s+\(
https://regex101.com/r/70N4wf/1

View solution in original post

0 Karma

FrankVl
Ultra Champion

If the latest occurrence is always at the start, it is fairly straightforward:

^"\d+\/\d+\/\d+\s+\d+:\d+:\d+\s+-\s+(?<name>[^\(]+)\s+\(
https://regex101.com/r/70N4wf/1

0 Karma

NicoloPunzalan2
Engager

Thanks Frank!

It works now.

0 Karma

sudosplunk
Motivator

I modified the regex a little so that it will take less steps to find the match.

This is the regex: ^"[\d\/\s\:]+-\s+(?<name>[\w\s]+)
https://regex101.com/r/70N4wf/3

0 Karma

FrankVl
Ultra Champion

Dangerous assumption that names don't contain anything but alphanumeric and spaces. Also, yours captures the trailing space behind the name (not sure if Splunk will automatically trim that perhaps?).

But the part before the name is indeed more efficient like this, thanks 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...