Splunk Search

How to extract string from a paragraph?

ppanchal
Path Finder

Hi,
Below is my paragraph and I want to extract the routeorder value from the paragraph.

Please assist.

other_app_launch_data:   Third Party App Launch Data:354736071554019 Data passed:Bundle{service_url : http://example.com/service; site_number : S04136; vehicle_id : 210648; driver_id : 082775; pre_post : post; tabletid : 354736071554019; first_name : Gennadiy; environment : Production; fuel : ; route_id : ***ROUTEORDER#**158682677**;*** device_id : 354736071554019; DVIR_RESPONSE_ACTION : DVIR_POST_CHECK_RESPONSE; meter_time : 717; meter_distance : 161724; last_name : Trofimchik;  }Bundle reqCode:9804
0 Karma
1 Solution

sudosplunk
Motivator

Hi there,

Try this,

your_search | rex field=_raw "route_id\s\:\s\w+\#(?<ROUTEORDER>\d+)"

View solution in original post

0 Karma

sudosplunk
Motivator

Hi there,

Try this,

your_search | rex field=_raw "route_id\s\:\s\w+\#(?<ROUTEORDER>\d+)"
0 Karma

ppanchal
Path Finder

No this did not work. I am not getting anything with the search.

0 Karma

sudosplunk
Motivator

Is it giving any error? Are able to see ROUTEORDER field under interesting fields section? Also, can you paste a screenshot of data along with your search.

0 Karma

ppanchal
Path Finder

yes, i got it thanks.

0 Karma

sudosplunk
Motivator

Great. Please accept the answer if it helped you.

0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...