- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

satishsdange
Builder
01-18-2016
01:28 AM
I am trying to extract username & password from below event -
form_key=6LgmjzGyzOYLIf11&login[username]=dev_lee@gmail.com&login[password]=password&send=
I am able to extract password properly but for username I am getting dev_lee%40gmail.com
instead of precise email ID.
Below is my regex
login.*?username.*?=(?<splUsername>.*?)&.*?login.*?password.*?=(?<splPassword>.*?)&
Could someone please help me fix the problem.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

esix_splunk

Splunk Employee
01-18-2016
03:52 AM
Try this in addition to the urldecode..
.. | rex field=_raw "login\[username\]\=(?<username>[^\&]+)\&login\[password\]\=(?<password>[^&]+)\&send" | eval mail=urldecode(username) | ..
That should fix you up.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

esix_splunk

Splunk Employee
01-18-2016
03:52 AM
Try this in addition to the urldecode..
.. | rex field=_raw "login\[username\]\=(?<username>[^\&]+)\&login\[password\]\=(?<password>[^&]+)\&send" | eval mail=urldecode(username) | ..
That should fix you up.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sebastian2
Path Finder
01-18-2016
02:29 AM
Looks like your event is url encoded. Have you tried to decode it? Try using the buildin urldecode?
When searching your data you could use it like:
... | eval mail = urldecode(mail) | ...
