Splunk Search

How to extract a string with regex?

dgillette3
Explorer

Hello!

I'm having trouble extracting the string "RES ONE Workspace Agent". Can anyone please tell me where I'm going wrong?

rex field=pluginText "(?P(^RES ONE Workspace Agent$))" 

[installed on 2017/11/09]\nRES ONE Workspace Agent [version 10.1.200.0]

Much appreciated!

0 Karma
1 Solution

FrankVl
Ultra Champion

Can you please use the code button (101010) to post any search queries and sample data? Looks like some special characters may have gotten lost!

^ and $ match start and end of the line. Since the string you want to extract is in the middle of the data, that doesn't work (assuming the sample you shared is the content of the pluginText field on which you apply the regex).

Probably this would work:

| rex field=pluginText "(?<fieldname>RES ONE Workspace Agent)"

Just out of curiosity: what is your purpose with extracting a literal string like that? Couldn't you just as well do: | eval field = "RES ONE Workspace Agent"?

View solution in original post

Kumar2
Loves-to-Learn Lots

@FrankVl In this way 

from_mail_id = MariaDubois@example.com
to_mail_id = zecora@buttercupgames.com

0 Karma

Kumar2
Loves-to-Learn Lots

Hi @FrankVl How to extract from and To fields For this below Line using Regex

Info: Bounced: DCID 8413617 MID 19338947 From: <MariaDubois@example.com> To: <zecora@buttercupgames.com> RID 0 - 5.4.7 - Delivery expired (message too old) ('000', ['timeout'])

Please help me with the Solution ,Thanks 

0 Karma

yeasuh
Splunk Employee
Splunk Employee

Hello! You may have better luck with your question if you post individually instead of as a reply! 

If you need help with anything- please don't hesitate to reach out! 

0 Karma

FrankVl
Ultra Champion

Can you please use the code button (101010) to post any search queries and sample data? Looks like some special characters may have gotten lost!

^ and $ match start and end of the line. Since the string you want to extract is in the middle of the data, that doesn't work (assuming the sample you shared is the content of the pluginText field on which you apply the regex).

Probably this would work:

| rex field=pluginText "(?<fieldname>RES ONE Workspace Agent)"

Just out of curiosity: what is your purpose with extracting a literal string like that? Couldn't you just as well do: | eval field = "RES ONE Workspace Agent"?

dgillette3
Explorer

Thank you Frank, worked like a charm.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...