Splunk Search

How to extract text from Message field

HMIPowell
Explorer

This should be something simple to figure out, but I can't get it to work.  I want to extract username from Message field of Sec Event Log

Labels (2)
0 Karma
1 Solution

HMIPowell
Explorer

I was able to use the following to get what I needed.

| rex field=Message "\S*user (?<TestField>\S*)"

Thanks for some of the ideas

View solution in original post

0 Karma

dhirendra761
Contributor
| makeresults 
| eval Message="NPS Extension for Azure MFA: CID: 6gof474f-4g9d-894f-asb-9abffedxs618 : Access Accepted for user Barry.Allen@LexLIndustries.org with Azure MFA response: Success and message: session r334r562-cf4f-7584-afc5-essdfs4dd67"
| rex field=Message "user (?<email>.*) with"
0 Karma

HMIPowell
Explorer

I was able to use the following to get what I needed.

| rex field=Message "\S*user (?<TestField>\S*)"

Thanks for some of the ideas

0 Karma

vaishalireddy
New Member

What is <TestField> here?

0 Karma

96nick
Communicator

Hey HMIPowell,

If your goal was to do this at search time (meaning in your search) you will use the rex command to accomplish this. There are multiple ways to do the regex and the final solution will depend on what the other logs in your search look like. One way to accomplish this field extraction is to use lookaheads and lookbehinds.

 

| yoursearch

| rex field=Message "((?<email>)?<=user)(.+?(?=with))"

| restofsearch

This will extract the email field by taking the text between (and not including) the words 'user' and 'with'. This may not work in your environment if other similar logs are present.

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...