Splunk Search

How to extract fields from regex and put in a table

splunkuser2127
Loves-to-Learn

My current search is:

 

index=rtm* source=/prod/msp/logs/private-auto-loan-credit* | regex "The rule (?<field1>[a-zA-Z0-9]+_[a-zA-Z0-9]+)_(?<field2>[a-zA-Z0-9]+) with" | table field1, field2

 

In verbose mode, it finds the correct entries, but my table is full of nulls. What am I doing wrong? 

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you share example events so the community could help you. 
You should change regex to rex and try again. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...