Splunk Search

How do I extract a comma separated field during search?

andyk
Path Finder

I have event data in Splunk that look like this:

2013-02-14 11:32:46.4314 app=ws3 sev=INFO mid=1325748 , Fooo, Barr, , 7 rue de fuubarr, , 44540, xx zzz la yyyyy, , FR, ENG, , 1031, EUR,,,

I need to do an Ad Hoc report that count the events grouped by country. The country information is in the filed that contains "FR" in this example event.

Tags (1)
0 Karma

rsantkumar
Observer

hi @jeff @andyk : I have 3 fields(Key, Version, Date) seperated by comma and records(can be many) seperated by ;(semicolon).

Example: pgn-aemrules,1.1,2020-04-02;pgn-csharp,8.4 (build 15306),2020-02-21;pgn-csharp,8.5 (build 15942),2020-03-16;

I am trying to extract the 3 fields and display as a table in splunk. Please help.

0 Karma

jeff
Contributor

Assuming all of your data has the same format:

{ search criteria } 
| rex field=_raw "^([^,]+,){9} +(?<country>[^,]+)"

rsantkumar
Observer

hi @jeff @andyk @Rob : I have 3 fields(Key, Version, Date) seperated by comma and records(can be many) seperated by ;(semicolon).

Example: pgn-aemrules,1.1,2020-04-02;pgn-csharp,8.4 (build 15306),2020-02-21;pgn-csharp,8.5 (build 15942),2020-03-16;

I am trying to extract the 3 fields and display as a table in splunk. Please help.

0 Karma

andyk
Path Finder

Works perfect! Thanks!

0 Karma

Rob
Splunk Employee
Splunk Employee

Nicely done!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...