Splunk Search

How to extract data using rex ?

anil1219
Engager

Hi,

I want to extract value c611b43d-a574-4636-9116-ec45fe8090f8 from below.

Could you please let me know how I can do using rex field=httpURL

 

httpURL: /peerpayment/v1/payment/c611b43d-a574-4636-9116-ec45fe8090f8/performAction

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Or better, do not use regex because the URI has an inherent structure/convention that many APIs adhere to. (See, e.g., Re: How do I modify my rex command to remove direc...)  What you ask is the second to last segment of HTTP_PATH variable in CGI standard.

| eval actionID = mvindex(split(httpURL, "/"), -2)

Semantic code is easier to maintain and in this case, potentially cheaper than regex. 

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @anil1219,

if the structure of the URL is fixed, you could use 

| rex "\/\w+\/\w+\/\w+\/(?<your_field>[^\/]+)"

that you can test at https://regex101.com/r/K3yj0E/1

Cio.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

New This Month - Observability Updates Give Extended Visibility and Improve User ...

This month is a collection of special news! From Magic Quadrant updates to AppDynamics integrations to ...

Intro to Splunk Synthetic Monitoring

In our last post, we mentioned that the 3 key pieces of observability – metrics, logs, and traces – provide ...