Splunk Search

How do I use rex command here?

harshal94
Engager

sample event:

fullFormattedMessage: Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds.

Required field is in bold.

0 Karma
1 Solution

poete
Builder

Hi,

try this

|  makeresults |  eval str="Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds"
|  rex field=str "microseconds to (?<value>\d+) microseconds"

View solution in original post

poete
Builder

Hi,

try this

|  makeresults |  eval str="Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds"
|  rex field=str "microseconds to (?<value>\d+) microseconds"

renjith_nair
Legend

Hi @harshal94 ,

If the format of the string going to be same, then you can use split also (much easier)

|stats count|eval xyz="fullFormattedMessage: Device naa.60000970000297500017533030313231 performance has improved. I/O latency reduced from 3746 microseconds to 1859 microseconds."|eval splitted=split(xyz," ")|eval micsecs=mvindex(splitted,mvcount(splitted)-2)
---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...