Splunk Search

Extract numeric values with in a field

iamsplunker
Communicator

We have a field called number and the field number has both alpha and numeric values like "number=AVAILABLE=25 USD;" and the field number also has multi values like number=" CREDIT_PAYMENT=200.22 USD; DEBIT_PAYMENT=500.10 USD;" also it has null values like number=null

I want to extract all dollar amounts like 25 and 200.22 and 500.10 and create a new field. How can I achieve this?

Please help

 

Labels (1)
0 Karma

renjith_nair
Legend

@iamsplunker,

Try and test against your data

|rex field=number max_match=0 "=(?<digits>\d+.?\d+|null)"
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...