Splunk Search

Help with regex needed

damucka
Builder

Hello,

 

We have Django logs in following format:

11/15/2021 08:34:38 [INFO - 171 ] - [tenant_move.py] - [STOP_PROCESS] : STOP_PROCESS(HANA Tenant Move Alerts) completed successfully - Rows affected : 1

and we would like to extract the following fields using regex, on the above example:

TYPE=INFO

LINE=171

SCRIPT=tenant_move.py

MODULE=STOP_PROCESS

.. ideally using single regex expression and not 4 separate.

Could anyone help?

Kind regards,

Kamil

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @damucka,

please try this regex:

| rex "\d+\/\d+\/\d+\s+\d+:\d+:\d+\s+\[(?<TYPE>\w+)\s+-\s+(?<LINE>\d+)[^\[]+\[(?<SCRIPT>[^\]]+)[^\[]+\[(?<MODULE>[^\]]+)"

that you can test at https://regex101.com/r/cM1Jwj/1

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @damucka,

please try this regex:

| rex "\d+\/\d+\/\d+\s+\d+:\d+:\d+\s+\[(?<TYPE>\w+)\s+-\s+(?<LINE>\d+)[^\[]+\[(?<SCRIPT>[^\]]+)[^\[]+\[(?<MODULE>[^\]]+)"

that you can test at https://regex101.com/r/cM1Jwj/1

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @damucka,

good for you, see next time!
Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...