Splunk Search

How can I extract additional fields from this source?

vinisha29
New Member

eg:
source = shuttle(Oct1-3).zip:./shuttle/5720/LOG/shuttle_log.20171002 ,shuttle_3.zip:./shuttle_3/5720/LOG/shuttle_log.20171011....etc
I want to extract folder _no : 5720

If possible please tell the regex expression to extract the fields
Pls help me.

Thanks

0 Karma

koshyk
Super Champion

Have a try regex of (Based on 5720 being the 2nd occurence in /)

(?:\/(.+?)){2}\/

https://regex101.com/r/kOJR7y/1

Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...