Splunk Search
Highlighted

How to extract portions of an event?

New Member

I have a event which is like below.

"searchString" index=ABC1............XYZ1"/searchString" 123456789 "searchString"index=ABC2.....................XYZ2"/searchString" 

I want to extract the data between "searchString" and "/searchString" .
the output should be like below

index=ABC1............XYZ1
index=ABC2.....................XYZ2
0 Karma
Highlighted

Re: How to extract portions of an event?

Legend

In you SPL, you could try this

.... | rex "searchString"\s(?<ss>[^"]*)"\/" | ...
0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.