Splunk Search

Help in Regex

vrmandadi
Builder

I have the field message - Method: Execute | Class: GetUsersByVinActivity
message- Method: Execute | Class: DecodeVinActivity

I want the method and class to extract as new fields from the message field

Thanks in advance

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi vrmandadi,

if the events are always in the format of the example you can use this regex:

 your search here to get the events 
| rex max_match=0 field=message "Method:\s(?<Method>[^\s]+)\s\|\sClass:\s(?<Class>[^\s]+)" 
| table _time Method Class

Hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi vrmandadi,

if the events are always in the format of the example you can use this regex:

 your search here to get the events 
| rex max_match=0 field=message "Method:\s(?<Method>[^\s]+)\s\|\sClass:\s(?<Class>[^\s]+)" 
| table _time Method Class

Hope this helps ...

cheers, MuS

vrmandadi
Builder

Thanks a lot Mus

0 Karma

jrbanks6
Explorer

^\w+\s+.\s+\w+.\s+\w+\s+\w+.\s+\w+.\s+(?\w+\s+).\s+\w+.\s+(?\w+)

This is a "Greedy" RegEx - Regex101.com is your friend!

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...