Splunk Search

Help with regular expression

indianhans
Engager

I wish to extract any number between "cmdbRequest" & "- Transaction" . For Example from below string

ERROR 21 CMDB cmdbRequest 1089798797 - Transaction Null: 10/21/2015 07:25:34 - Exception: ORA-12578: TNS:wallet open failed

i wish to extract 1089798797

i have wrtten below regular expression to get the number, but its giving me a null value.

| rex "CMDBRequest(?P<Request_ID>.*?)Transaction" |

Can anyone please help ?

0 Karma

bevant
Explorer

won't you need to cater for the stuff either side (spaces/dashes?

rex "cmdbRequest\s(?<Request_ID>\d+)\s\-\sTransaction"

...or something like that, depending on how consistent you expect it to all be. I've not tested it, but it might put you on the correct path

0 Karma

abhijitmishra87
Explorer

Please try the following :

| rex "cmdbRequest(?P<Request_ID>\d+)Transaction" |
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...