Splunk Search

How to extract fields with a trailing space after the delimiter character "=" (ex: Code= 999)?

arnabsen1234
New Member

Hi All,

I have a snippet as below :

  requestId="8b749da4-2996-437f-954d-2b679cd3239b"  Transaction Id= 1234, Alpha= 56789, Beta= 09876, Code= 999

I want to extract this Code.
Please note that "Code" has trailing = with space.

How do I extract this?

0 Karma

bmacias84
Champion

try this one

 ... | rex field=_raw "Code=\s+(?<code>[^\s,]+)" | table code
0 Karma

sk314
Builder

Try this:

... | rex field=_raw "Code=\s*(?<code>\d+)" | table code
0 Karma

arnabsen1234
New Member

This does not seem to be working. I am getting blank blank values for code

0 Karma

sk314
Builder

Could you post a sample event in its entirety?

0 Karma

somesoni2
Revered Legend
Try replacing \d+ with \w+ 
0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...