Splunk Search

Extract a string

rbachu1
Explorer

Hi everyone, I have the below string.

isadhakdahdj asdh, hosadhao activity=Follow Up, entryName=Initial Outreach, asasa adadad oidaoidadalnd.

I want to extract .

activity=Follow Up

entryName=Initial Outreach

activity & entryName are static, but value of that may be dyna

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex "activity=(?<activity>[^,]+),\sentryName=(?<entryName>[^,]+),"

View solution in original post

0 Karma

rbachu1
Explorer

Thank you so much, exactly what I needed.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "activity=(?<activity>[^,]+),\sentryName=(?<entryName>[^,]+),"
0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...