Splunk Search

How to extract fields with a trailing space after the delimiter character "=" (ex: Code= 999)?

arnabsen1234
New Member

Hi All,

I have a snippet as below :

  requestId="8b749da4-2996-437f-954d-2b679cd3239b"  Transaction Id= 1234, Alpha= 56789, Beta= 09876, Code= 999

I want to extract this Code.
Please note that "Code" has trailing = with space.

How do I extract this?

0 Karma

bmacias84
Champion

try this one

 ... | rex field=_raw "Code=\s+(?<code>[^\s,]+)" | table code
0 Karma

sk314
Builder

Try this:

... | rex field=_raw "Code=\s*(?<code>\d+)" | table code
0 Karma

arnabsen1234
New Member

This does not seem to be working. I am getting blank blank values for code

0 Karma

sk314
Builder

Could you post a sample event in its entirety?

0 Karma

somesoni2
Revered Legend
Try replacing \d+ with \w+ 
0 Karma
Get Updates on the Splunk Community!

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...