- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
scout29
Path Finder
11-22-2024
08:28 AM
Need help to extract a field that comes after a certain word in a event.
I am looking to extract a field called "sn_grp" with the value of "M2 Infra Ops". So for every event that has sn_grp: i would like to extract the string that follows of "M2 Infra Ops". This string value will be the same name for every event.
Below is an example data set i am using to write the regex to
\"sn_grp:M2 Infra Ops\"},{\"context\":\"CONTEXTLESS\",\"key\":\"Correspondence Routing Engine\
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
11-22-2024
08:37 AM
This should get you started.
| rex "sn_grp:(?<sn_grp>[^\\]+)"
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
11-22-2024
08:37 AM
This should get you started.
| rex "sn_grp:(?<sn_grp>[^\\]+)"
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
scout29
Path Finder
11-22-2024
09:04 AM
That seems to work however it is capturing the "\" in the string at the end. I want the value to stop after Ops in the string and not include the "\"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
11-22-2024
09:06 AM
Try my revised answer.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
