Splunk Search

Help with rex on raw data

Path Finder


I have data like this I want to display middlename and lastname from the below info.
please help me out in writing rex for below raw data


Tags (2)
0 Karma

Splunk Employee
Splunk Employee

Hey @sravankaripe, If @gokadroid's solution worked then please don't forget to accept his answer to award karma points and close the question. 🙂

0 Karma


May you try this below please:

your query to return events
| rex "\\\"middleName\\\":\\\"(?<mn>[^\\]+)\\\",\\\"lastName\\\":\\\"(?<ln>[^\\]+)\\\""
| table mn, ln

See extractions here

0 Karma