Splunk Search

Field Extraction using Regex

abilann
New Member

Hi Team,

I would like to extract table name from below combined event using rex. Both events are combined in one event using transaction. Can you please help,

25324/-285213840 WRK:DF_E4CAC858_tor Thu Apr 9 23:17:25.077194 dbprq.c770
doQueryDiagnostics: The following SQL query took 535 seconds which is equal to or greater than QueryExecutionTimeThreshold (4 seconds) for User(AF) with DBProxyUser(AF).
25324/-285213840 WRK:AF_E4CAC858_tor Thu Apr 9 23:17:25.080304 dbpq.c782
SELECT * FROM PRODDTA.Employee WHERE ( A=1 )

Thanks,
Abilan

0 Karma

richgalloway
SplunkTrust
SplunkTrust

See if this helps.

... | rex "(?i)FROM (?<table>\S+)"
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...