Splunk Search

Extracting a number a my query not working

ramkrishs
New Member

Hi i have a log like this  Elapsed time: prediction timer 0.1953 seconds 

 

and i created a rex like this rex "Elapsed\stime:\sprediction\stimer\s(?<predictionTime>\d+)\sseconds"

 

but i am unable to find the value at all what am i missing here ? any help would be appreciated 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Your regex specifies that your capture group consists of digits only (at least one digit) and then immediately you get a space.

In your event you have a decimal fraction as well.

So you need

\d+(\.\d+)?
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...