Splunk Search

Extracting text from event using search

fabiozihlmann
Engager

Hi I am trying to make a dashboard that searches events and extracts the correlationId from the event so I can display that information in a cleaner manner.  I just want to be able to extract the correlationId using my search and it comes in two main patterns. 

The first event pattern 

fabiozihlmann_2-1598973973588.png

 

and the second pattern

fabiozihlmann_1-1598973907266.png

 

My current search is 

fabiozihlmann_3-1598974103838.png

My ultimate goal is to make a table with a Correlation ID column and other vital information columns

 

I have not edited the source code yet, so please feel free to leave any feedback or clarifying questions if needed

Labels (4)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please post text rather than screen shots so we can use it in test cases.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

 

| rex "correlationId(='| )(?<correlationId>[0-9a-fA-F-]+)"

Single quote might need escaping with a back-slash i.e. (=\'| )

 

Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...