Splunk Search

How to extract text from Message field

HMIPowell
Explorer

This should be something simple to figure out, but I can't get it to work.  I want to extract username from Message field of Sec Event Log

Labels (2)
0 Karma
1 Solution

HMIPowell
Explorer

I was able to use the following to get what I needed.

| rex field=Message "\S*user (?<TestField>\S*)"

Thanks for some of the ideas

View solution in original post

0 Karma

dhirendra761
Contributor
| makeresults 
| eval Message="NPS Extension for Azure MFA: CID: 6gof474f-4g9d-894f-asb-9abffedxs618 : Access Accepted for user Barry.Allen@LexLIndustries.org with Azure MFA response: Success and message: session r334r562-cf4f-7584-afc5-essdfs4dd67"
| rex field=Message "user (?<email>.*) with"
0 Karma

HMIPowell
Explorer

I was able to use the following to get what I needed.

| rex field=Message "\S*user (?<TestField>\S*)"

Thanks for some of the ideas

0 Karma

vaishalireddy
New Member

What is <TestField> here?

0 Karma

96nick
Communicator

Hey HMIPowell,

If your goal was to do this at search time (meaning in your search) you will use the rex command to accomplish this. There are multiple ways to do the regex and the final solution will depend on what the other logs in your search look like. One way to accomplish this field extraction is to use lookaheads and lookbehinds.

 

| yoursearch

| rex field=Message "((?<email>)?<=user)(.+?(?=with))"

| restofsearch

This will extract the email field by taking the text between (and not including) the words 'user' and 'with'. This may not work in your environment if other similar logs are present.

 

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...