Splunk Search

How to convert a working rex statement to a field extraction?

ebailey
Communicator

Sample data:

12/28/2015 11:39:14.113 -0600
collection="MSMQ Queue"
object="MSMQ Queue"
counter="Messages in Queue"
instance="hostname"\private$\test_test_1062
Value=4

I have a working rex that extracts test_test_1062 to the following:

queueName=test_test_1062

using this rex:

| rex field=instance \\\(?<queueName>[^\\]+)$\"

If I try to convert this to a field extraction, I get the following error message

Encountered the following error while trying to update: In handler 'props-extract': Regex: unmatched parentheses

If I remove a slash from each group of slashes then I can save the field extraction, but then the result is not accurate and the last line is captured so I get this

queueName=test_test_1062 Value=4

The instance field has several variations, so I cannot get the IFX to work correctly once I load all the variations into it. Basically I just need all the text after private$ until a white space occurs, but I cannot figure out how to make that happen and also work as a field extraction.

Thanks!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

This worked for me. I just replaced the '$' with '\s' to get everything until the next white space.

\\(?<queueName>[^\\]+)\s
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

This worked for me. I just replaced the '$' with '\s' to get everything until the next white space.

\\(?<queueName>[^\\]+)\s
---
If this reply helps you, Karma would be appreciated.

ebailey
Communicator

perfect - thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...