Splunk Search

Hello, I need help to extract a value from a string

flck
Path Finder

Hi everyone,


I hope someone can help me with the following situation.
I have multiple events generated from Azure Devops like the following:

{"system.pullRequest.pullRequestId":"223033","system.pullRequest.sourceBranch":"refs/heads/release","system.pullRequest.targetBranch":"refs/heads/master","system.pullRequest.sourceCommitId":"e000000a962ff66c19aacXXXXXXX4c7","system.pullRequest.sourceRepositoryUri":"https://siteXXX.visualstudio.com/XXXX%XXX%20ds%XXXX%C3%ADa/_git/AWXXX000","system.pullRequest.pullRe..."}

 

I am trying to extract the value that corresponds to the field "system.pullRequest.pullRequestId", for this example it is "223033", I have not been able to achieve it yet. Any idea how to do it?

For some events the field "system.pullRequest.pullRequestId" is not at the beginning of the string, it can be in the middle or at the end, the position varies with each event.

I appreciate any help you can give me.

Labels (3)
1 Solution

flck
Path Finder

Hi,


Thanks for your answer, I tested the rex and it only counts but it does not extract the field I need. Trying a little more I was able to extract it like this:

... | eval _raw = parameters | extract

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @flck ..

may we know what output you get with this above rex query. 

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "system\.pullRequest\.pullRequestId\":\"(?<pullrequestid>\d+)\""

flck
Path Finder

Hi,


Thanks for your answer, I tested the rex and it only counts but it does not extract the field I need. Trying a little more I was able to extract it like this:

... | eval _raw = parameters | extract

0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...