Hi all,
I'm new to splunk and i had hard time extracting fields using regex for the following example :
Class (six, seven)
Can someone help me with the above example , i want class as a field name and six,seven as two values for the field class.
Thanks for the help in Advance.
| rex "Class\s+\((?<Class>[^\)]+)"
| makemv Class delim=","
| mvexpand Class
| rex "Class\s+\((?<Class>[^\)]+)"
| makemv Class delim=","
| mvexpand Class
Good place to test these is https://regex101.com/
r. Ismo