Splunk Search

How do i extract field usinng regex .

bpot
Engager

Hi all,

I'm new to splunk and i had hard time extracting fields  using regex for the following example :
Class (six, seven)

Can someone help me with the above example , i want class as a field name and six,seven as two values for the field class.

Thanks for the help in Advance.

Labels (4)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

| rex "Class\s+\((?<Class>[^\)]+)"

| makemv Class delim=","

| mvexpand Class

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

| rex "Class\s+\((?<Class>[^\)]+)"

| makemv Class delim=","

| mvexpand Class

————————————
If this helps, give a like below.

isoutamo
SplunkTrust
SplunkTrust

Good place to test these is https://regex101.com/

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...