Splunk Search
Highlighted

How to extract the field?

Builder

How to extract the user(splunk) from the below field?

(ABCDEFG\splunk)

0 Karma
Highlighted

Re: How to extract the field?

SplunkTrust
SplunkTrust

Try this

your search | rex field=yourfield "\\\(?<user>\w+)\)"

Other methods

your search | eval user=replace(yourfield, "^.+\\\(\w+)\)","\1")

your search | eval user=rtrim(mvindex(split(yourfield,"\\"),-1),")")

View solution in original post