Splunk Search

How do I extract the latest occurrence of a field from multiple lines?

nkchaitanya
Explorer

Want to capture the latest occurrence of "working_condition_check - status -" which is "Stopped".

Please help me in getting the regex.

Below is the log message.

10/01/2018 15:01:04 Server_Name
working_condition_check - status - Started
working_condition_check - status - Running
working_condition_check - status - Stopped

0 Karma

harishalipaka
Motivator

hi @nkchaitanya

As @493669 answer follow that end of your query add this

| makeresults |eval hari="working_condition_check - status - Stopped" |rex field=hari ".*status - (?<status>\w+)" |where status="Stopped"
Thanks
Harish
0 Karma

493669
Super Champion

Hi @nkchaitanya,
Try this:

...|rex ".*status - (?<status>\w+)"
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...