Splunk Search
Highlighted

How can I extract string between highlighted fields with regex?

Explorer

Error: Update failed. First exception on row 0 with id abcd; first error: INVALIDEMAILADDRESS, Email: invalid email address: jrwils@secuamp;gt;: [Email]

0 Karma
Highlighted

Re: How can I extract string between highlighted fields with regex?

SplunkTrust
SplunkTrust

Hi @vik123ash,

You can use below query to extract email address in new field called Email

... <your search> ... | rex field=_raw "(?:[^\:]*\:){4}(?<Email>.*)\["

I hope this helps.

Thanks,
Harshil

0 Karma
Highlighted

Re: How can I extract string between highlighted fields with regex?

Legend

Hi vik123ash,
you can use

invalid\semail\saddress:\s(?<invalid_email>[^\[]*)\[Email\]

test it at https://regex101.com/r/hUzreZ/2

Bye.
Giuseppe

View solution in original post

0 Karma
Highlighted

Re: How can I extract string between highlighted fields with regex?

Explorer

Thanks Giuseppe

0 Karma