Splunk Search

How to extract password field in the events with regex? (Password is a string of numbers)

kiran331
Builder

How to extract password field in the events?

I need to extract " 123456-222245-666565-151063-123456-222365-333111-110110" from below sample event. Any ideas?

==========================
BitLocker Drive Encryption: Configuration Tool version 10.0.15063
Copyright (C) 2013 Microsoft Corporation. All rights reserved.
Computer Name: abcde
Volume C: [dfdf]
All Key Protectors
Numerical Password:
ID: {fjkfjsdfsdjfsj,fhndhg}
Password:
123456-222245-666565-151063-123456-222365-333111-110110
TPM:
ID: {vgdsfsdf3D-33dfdsf44F0-A1EBf9A4B88FFF9A8}
PCR Validation Profile:
0, 2, 4, 11
abcde

Thanks
Kiran

Tags (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi kiran331,
try this:

(?ms)\}\s+Password:\s+(?<Password>.*)TPM

or

| rex "(?ms)\}\s+Password:\s+(?<Password>.*)TPM"

you can test it at https://regex101.com/r/5Wp6Tw/1

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi kiran331,
try this:

(?ms)\}\s+Password:\s+(?<Password>.*)TPM

or

| rex "(?ms)\}\s+Password:\s+(?<Password>.*)TPM"

you can test it at https://regex101.com/r/5Wp6Tw/1

Bye.
Giuseppe

0 Karma

sbbadri
Motivator

@kiran331

your search | rex field=_raw "Password:\s+(?P<password>.+)\s+TPM:

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...