Splunk Search

How to Extract fields with alphanumeric values?

inkedia
Explorer

 

 

 

 



I have to extract the highlighted value as a single field in splunk. Any help.

Labels (1)
0 Karma
1 Solution

venky1544
Builder

hi @inkedia 

try the below search 

your search  |rex field=_raw max_match=0 "(?<taskid>TASK\d+)"|table taskid

 

venky1544_0-1649864008740.png

if this help karma points are  appreciated /accept the solution it might help others 

View solution in original post

inkedia
Explorer

supper helpful... thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Nothing is highlighted.  Please specify what you are trying to extract, how you've tried to extract it, and how those attempts failed to meet expectations.

---
If this reply helps you, Karma would be appreciated.
0 Karma

inkedia
Explorer

Sorry but my I wanted info as to how to extract the values starting with TASK...... they are the bolded stuff

0 Karma

venky1544
Builder

hi @inkedia 

try the below search 

your search  |rex field=_raw max_match=0 "(?<taskid>TASK\d+)"|table taskid

 

venky1544_0-1649864008740.png

if this help karma points are  appreciated /accept the solution it might help others 

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...