Splunk Search

How to extract a string from a field using Splunk Regex?

deepaksn1214
Engager

I m having a hard time trying to extract a string from a field from a splunk search using splunk regex , can someone help pls ? 

The field looks like client_info=xxx-yyy=aaaa-bbb-cccc::4.144.1::web-app-id::plugin-id

I just want the string web-app-id and plugin-id extracted in separate fields named WebApp and Plugin

Appreciate any help on this , thanks in advance ! 

Labels (3)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "::(?<WebApp>[^:]+)::(?<Plugin>[^:]+)$"
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...