Splunk Search

Hello, I need help to extract a value from a string

flck
Path Finder

Hi everyone,


I hope someone can help me with the following situation.
I have multiple events generated from Azure Devops like the following:

{"system.pullRequest.pullRequestId":"223033","system.pullRequest.sourceBranch":"refs/heads/release","system.pullRequest.targetBranch":"refs/heads/master","system.pullRequest.sourceCommitId":"e000000a962ff66c19aacXXXXXXX4c7","system.pullRequest.sourceRepositoryUri":"https://siteXXX.visualstudio.com/XXXX%XXX%20ds%XXXX%C3%ADa/_git/AWXXX000","system.pullRequest.pullRe..."}

 

I am trying to extract the value that corresponds to the field "system.pullRequest.pullRequestId", for this example it is "223033", I have not been able to achieve it yet. Any idea how to do it?

For some events the field "system.pullRequest.pullRequestId" is not at the beginning of the string, it can be in the middle or at the end, the position varies with each event.

I appreciate any help you can give me.

Labels (3)
1 Solution

flck
Path Finder

Hi,


Thanks for your answer, I tested the rex and it only counts but it does not extract the field I need. Trying a little more I was able to extract it like this:

... | eval _raw = parameters | extract

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @flck ..

may we know what output you get with this above rex query. 

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "system\.pullRequest\.pullRequestId\":\"(?<pullrequestid>\d+)\""

flck
Path Finder

Hi,


Thanks for your answer, I tested the rex and it only counts but it does not extract the field I need. Trying a little more I was able to extract it like this:

... | eval _raw = parameters | extract

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...