Splunk Search

How to extract text from Message field

HMIPowell
Explorer

This should be something simple to figure out, but I can't get it to work.  I want to extract username from Message field of Sec Event Log

Labels (2)
0 Karma
1 Solution

HMIPowell
Explorer

I was able to use the following to get what I needed.

| rex field=Message "\S*user (?<TestField>\S*)"

Thanks for some of the ideas

View solution in original post

0 Karma

dhirendra761
Contributor
| makeresults 
| eval Message="NPS Extension for Azure MFA: CID: 6gof474f-4g9d-894f-asb-9abffedxs618 : Access Accepted for user Barry.Allen@LexLIndustries.org with Azure MFA response: Success and message: session r334r562-cf4f-7584-afc5-essdfs4dd67"
| rex field=Message "user (?<email>.*) with"
0 Karma

HMIPowell
Explorer

I was able to use the following to get what I needed.

| rex field=Message "\S*user (?<TestField>\S*)"

Thanks for some of the ideas

0 Karma

vaishalireddy
New Member

What is <TestField> here?

0 Karma

96nick
Communicator

Hey HMIPowell,

If your goal was to do this at search time (meaning in your search) you will use the rex command to accomplish this. There are multiple ways to do the regex and the final solution will depend on what the other logs in your search look like. One way to accomplish this field extraction is to use lookaheads and lookbehinds.

 

| yoursearch

| rex field=Message "((?<email>)?<=user)(.+?(?=with))"

| restofsearch

This will extract the email field by taking the text between (and not including) the words 'user' and 'with'. This may not work in your environment if other similar logs are present.

 

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...