Splunk Search

Filed extraction assistance

gerald_huddlest
Path Finder

iam trying to extarct the room name fromt eh string below but the automatioc filed extraction does not fined enough examples due to numerous other messages in logs.

"chat://room/domain/roomname"

I created a filed extraction to extract the domain, called domain but am not able to get splunk to extract the room name.

need to extract all characters between the last / and the ".

appreciate your help

Tags (1)
0 Karma

Damien_Dallimor
Ultra Champion

Here is a very simple regex , to get you started, that will extract the roomname value out to the field "roomname_field"

"chat://\w+/\w+/(?<roomname_field>\w+)"

Without seeing a sample of many possible values I dont know what characters could be in the room, domain and roomname path parts. \w just captures [a-zA-Z_0-9] . Adjust as necessary.

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...