Splunk Search

How could extract a new field from a sentence which contains the expression of the value?

Jennifer
Path Finder

Hi, all!

Here's my log file:

- the pattern: raw call progress sequence is: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

- the length of the value of the raw call progress sequence might differ from each other

My request is how could I extract the highlighted part as a new filed!!!

2022-02-07 16:27:49,423|tOX-u3JFAq6EmU3FXYy-Td2|DEBUG|com.hsbc.hvf.mi.MIAPI|endCallMI()|MI insertion started... 2022-02-07 16:27:49,423|tOX-u3JFAq6EmU3FXYy-Td2|DEBUG|com.hsbc.hvf.mi.MIAPI|endCallMI()|raw call progress sequence is:31381113209410021947204792292008771577067705W019W021W023W02099529959 

raw call progress sequence is:31381116209410122047922920012099215396732101210296887903763575957598W016E194Q098U165W023A024995299563173

raw call progress sequence is:313811112094100231941577

raw call progress sequence is:313811162094100219472047922920012099215396732101210296889296961877197902790876367637W016E191Q064U086W023A70299529956653765386604W016CS00E191Q064U086W023A7029952995665376538

 

Labels (2)
Tags (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust
raw\scall\sprogress\ssequence\sis:\s(?<progress_sequence>\S+)

I'm not fully sure from your examples whether there should be \s or not between : and (

View solution in original post

PickleRick
SplunkTrust
SplunkTrust
raw\scall\sprogress\ssequence\sis:\s(?<progress_sequence>\S+)

I'm not fully sure from your examples whether there should be \s or not between : and (

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...