Splunk Search

Grep a part of the multiline event.

sarvan7777
New Member

I want to strip few rows from my log file and create a report in Splunk. Here is a sample even.

blah blah blah
blah blah blah
COUNT TOPIC COMPONENT

======= =========== ==========
586 ABC DEF
231 MNO XYZ
blah blah blah
blah blah blah

All I need is the fields count, topic and component along with the values in my report. Any input is highly appreciated

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Like this:

Your Base Search Here
| rex "(?msi)^COUNT\s+TOPIC\s+COMPONENT[\r\n\s=]+(?<COUNT1>\S+)\s+(?<TOPIC1>\S+)\s+(?<COMPONENT1>\S+)[\r\n\s=]+(?<COUNT2>\S+)\s+(?<TOPIC2>\S+)\s+(?<COMPONENT2>\S+)"

You now have fields: COUNT1, TOPIC1, COMPONENT1, COUNT2, TOPIC2, and COMPONENT2.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

Your Base Search Here
| rex "(?msi)^COUNT\s+TOPIC\s+COMPONENT[\r\n\s=]+(?<COUNT1>\S+)\s+(?<TOPIC1>\S+)\s+(?<COMPONENT1>\S+)[\r\n\s=]+(?<COUNT2>\S+)\s+(?<TOPIC2>\S+)\s+(?<COMPONENT2>\S+)"

You now have fields: COUNT1, TOPIC1, COMPONENT1, COUNT2, TOPIC2, and COMPONENT2.

0 Karma

sarvan7777
New Member

This is just what I want. Thanks for your response

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...