Splunk Search

How do I use rex command here?

harshal94
Engager

sample event:

fullFormattedMessage: Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds.

Required field is in bold.

0 Karma
1 Solution

poete
Builder

Hi,

try this

|  makeresults |  eval str="Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds"
|  rex field=str "microseconds to (?<value>\d+) microseconds"

View solution in original post

poete
Builder

Hi,

try this

|  makeresults |  eval str="Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds"
|  rex field=str "microseconds to (?<value>\d+) microseconds"

renjith_nair
Legend

Hi @harshal94 ,

If the format of the string going to be same, then you can use split also (much easier)

|stats count|eval xyz="fullFormattedMessage: Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds."|eval splitted=split(xyz," ")|eval micsecs=mvindex(splitted,mvcount(splitted)-2)
---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...