Splunk Search

How to edit my rex statement to extract the name out of this example string?

packet_hunter
Contributor

I am trying to rex out a person name out of the following....

.... @ xyz-2\\\\johndoe&........

Here is my current search:

sourcetype=A_cef_syslog category="ThisONe" | rex field=ThatONe "\@(?[\w+\d\-\\ ]+) " | stats list(person)

Ideally I would like the match to start with @ and stop at &...

Any help is much appreciated,

thank you!!!

0 Karma
1 Solution

sundareshr
Legend

Try this

... | rex field=ThatONe "@(?<name>[^\&]+)" | ...

View solution in original post

0 Karma

sundareshr
Legend

Try this

... | rex field=ThatONe "@(?<name>[^\&]+)" | ...
0 Karma

packet_hunter
Contributor

Thank you!!!

Lately I have been using online regex tester to test my rex code but apparently what works in the online tester doesn't always work... any other testing suggestions other than the obvious- "RTFM again" (which I am going to do)?

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...