Splunk Search

Extract data from a string that has variable length

madakkas
Explorer

Hi I have the below data , and am trying to extract the below

Start lsakjdf sdlkj sd CODE=CODE1 ksdjf ksajfd sakjdf
Start $jdf$ ssfjdlkj sd CODE=CODE2 ksdjf ksajfd sakjdf
Start lsakjdf CODE=CODE3 ksdjf ksajfd sakjdf
Start lsakj44 sdlkj sdah sd CODE=CODE4 ksdjf ksajfd sakjdf

CODE=CODE1
CODE=CODE2
CODE=CODE3
CODE=CODE4

Tags (1)
0 Karma
1 Solution

p_gurav
Champion

Did you try below regex:

| rex field=_raw "(?P<data>\w+=\w+)"

View solution in original post

0 Karma

p_gurav
Champion

Did you try below regex:

| rex field=_raw "(?P<data>\w+=\w+)"
0 Karma

madakkas
Explorer

that did work ,

I set it up using the below as well

|eval CODE = trim(substr(mvindex(split(MSGTXT," "),mvfind(split(MSGTXT," "),"CODE=")),0,10))

0 Karma

damien_chillet
Builder

Are you looking for a regex? (?P<data>\w+=\w+) maybe?

0 Karma

madakkas
Explorer

I am fine with any approach as far as i get my result.

regex as well is fine.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...