Splunk Search
Highlighted

Help with rex on raw data

Path Finder

Hi,

I have data like this I want to display middlename and lastname from the below info.
please help me out in writing rex for below raw data

\"middleName\":\"L\",\"lastName\":\"CRIB\"

Tags (2)
0 Karma
Highlighted

Re: Help with rex on raw data

Motivator

May you try this below please:

your query to return events
| rex "\\\"middleName\\\":\\\"(?<mn>[^\\]+)\\\",\\\"lastName\\\":\\\"(?<ln>[^\\]+)\\\""
| table mn, ln

See extractions here

0 Karma
Highlighted

Re: Help with rex on raw data

Motivator

Hey @sravankaripe, If @gokadroid's solution worked then please don't forget to accept his answer to award karma points and close the question. 🙂

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.