Splunk Search

How to extract fields with a trailing space after the delimiter character "=" (ex: Code= 999)?

arnabsen1234
New Member

Hi All,

I have a snippet as below :

  requestId="8b749da4-2996-437f-954d-2b679cd3239b"  Transaction Id= 1234, Alpha= 56789, Beta= 09876, Code= 999

I want to extract this Code.
Please note that "Code" has trailing = with space.

How do I extract this?

0 Karma

bmacias84
Champion

try this one

 ... | rex field=_raw "Code=\s+(?<code>[^\s,]+)" | table code
0 Karma

sk314
Builder

Try this:

... | rex field=_raw "Code=\s*(?<code>\d+)" | table code
0 Karma

arnabsen1234
New Member

This does not seem to be working. I am getting blank blank values for code

0 Karma

sk314
Builder

Could you post a sample event in its entirety?

0 Karma

somesoni2
Revered Legend
Try replacing \d+ with \w+ 
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...