Splunk Search

How to extract field from source field?

ravir_jbp
Explorer

I am trying extract "user20" from rest of "_9a4ab75c_239_process.log".  tried multiple ways but unable to separate the user name from underscore.

 

/app_5/appname/appanem2/logs/agent-machine4/sre/query/prot/user20_tt65rft67uu87_process.log"

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=source "/(?<user>[^_/]+)[^/]+\.log$"
0 Karma
Get Updates on the Splunk Community!

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...

Getting Started with Splunk Artificial Intelligence, Insights for Nonprofits, and ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...