Splunk Search

How to edit my rex to receive values for Start Date and End Date?

New Member

Rex expression used : startDate= (?.*) endDate= (?.*)

Data format : &startDate=10/02/2016&endDate=10/02/2016&

Don't get any values back for the Start Date and End Date columns..

What is wrong? Thanks in advance

Radhak

Tags (2)
0 Karma
1 Solution

Motivator

Try:

\&startDate\=(?<startDate>[^\&]+)\&endDate\=(?<endDate>[^\&]+)\&

View solution in original post

0 Karma

Legend

Try this

| rex "startDate=(?<start>\d\d\/\d\d\/\d\d\d\d)\&endDate=(?<end>\d\d\/\d\d\/\d\d\d\d)"
0 Karma

New Member

Thanks worked as well.

0 Karma

Motivator

Try:

\&startDate\=(?<startDate>[^\&]+)\&endDate\=(?<endDate>[^\&]+)\&

View solution in original post

0 Karma

New Member

Thank you . Worked great !

0 Karma

Motivator

you are welcome.

0 Karma