Splunk Search

How to Extract Named Capture Groups Using a Single Line in Props.conf

Kcrowley55
New Member

Trying to extract named capture groups in a txt file, with the stipulation that it must be done from a single line in props.conf. The exercise is designed to teach how to assign many fields/values in a single line of RegEx.

There are around 20 or so fields we need to extract from the txt file (all the fields are outlined a single "event" in the text file along with the accompanying values in the next "event:). We are assuming that some form of EXTRACT will be used in props, but just not sure how to format in a single line. Any help or guidance would be much appreciated!

Tags (1)
0 Karma

somesoni2
Revered Legend

Please share some sample log entries from which you want to extract fields. Mask anything sensitive.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...