Splunk Search

How to extract fields with a trailing space after the delimiter character "=" (ex: Code= 999)?

arnabsen1234
New Member

Hi All,

I have a snippet as below :

  requestId="8b749da4-2996-437f-954d-2b679cd3239b"  Transaction Id= 1234, Alpha= 56789, Beta= 09876, Code= 999

I want to extract this Code.
Please note that "Code" has trailing = with space.

How do I extract this?

0 Karma

bmacias84
Champion

try this one

 ... | rex field=_raw "Code=\s+(?<code>[^\s,]+)" | table code
0 Karma

sk314
Builder

Try this:

... | rex field=_raw "Code=\s*(?<code>\d+)" | table code
0 Karma

arnabsen1234
New Member

This does not seem to be working. I am getting blank blank values for code

0 Karma

sk314
Builder

Could you post a sample event in its entirety?

0 Karma

somesoni2
Revered Legend
Try replacing \d+ with \w+ 
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...