Splunk Search

How to extract fields from regex and put in a table

splunkuser2127
Loves-to-Learn

My current search is:

 

index=rtm* source=/prod/msp/logs/private-auto-loan-credit* | regex "The rule (?<field1>[a-zA-Z0-9]+_[a-zA-Z0-9]+)_(?<field2>[a-zA-Z0-9]+) with" | table field1, field2

 

In verbose mode, it finds the correct entries, but my table is full of nulls. What am I doing wrong? 

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you share example events so the community could help you. 
You should change regex to rex and try again. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...