i have these log entries, and I'm trying to extract the underlined data as "Business_Process"
i'm using the below regex, on geg101 it extracts just fine but on splunk it exctracts a huge chunk.
rex field=_raw "\Drun\.name\D:\D(?<Business_Process>.+)\D,\Drun.u"
i get below result in splunk
| rex “run\.name\”:\”(?<Business_Process>[^\”]+)”
don’t forget to replace double quotes from your keyboard. Double quotes may not match as I am typing from them my phone.
| rex “run\.name\”:\”(?<Business_Process>[^\”]+)”
don’t forget to replace double quotes from your keyboard. Double quotes may not match as I am typing from them my phone.
having same issue, trying to extract red text
"run\.author\.fullname\D:\"(?<USER>.+\"\,\"r)"
just advice - don't post actual data here.
| rex “run\.author\.fullname\”:\”(?<User>[^\”]+)”
Hi thanks for the advice, seem to be getting an error on that regex
| rex "run\.author\.fullname\":\"(?<User>[^\"]+)"
try now. the issue is with double quotes, as I had typed them from my phone.
Yes I figured it was that, sorry to be bothersome.. any idea how can i vizualize a relationship between Business_Process and User ? i want to show in a cool way which user ran which business process
| stats values(Business_process) as business_process by User
wow thanks bro works perfectly, how can i learn to perfect my regex skills?