Splunk logs looks like below:
userid=234user|rwe23|dwdwd --
userid=id123|34lod|2323 textHow can I get value between "=" and first "|"
I want to get table of value between "=" and first "|", like "234user" and "id123"
I tried:
index=indexhere "userid=" |regex "(?<==)(?<info>.+?)(?=\|)"
| dedup info
| table info
this one works fine in regex101, but shows 0 result in Splunk.
Could anyone please help? Any help would be appreciated. Thanks!
Yes..seems like I am looking for rex not regex. Thanks for helping.
The regex command filters events - it does not extract fields. To extract fields, use the rex command. Also, avoid lookbehind in regexes - they're not necessary and take longer to process.
index=indexhere "userid="
| rex "userid=(?<info>[^\|]+?)"
| dedup info
| table info