Splunk Search

How to extract the hostname value into a separate field using regex?

Communicator

Hello - I need help extracting the "hostname" value into a separate field in the following string:

 

ABC1234: VPN Tunneling: Session started for user with IPv4 address 10.10.10.10, hostname jsmith-1234s

 

 

Labels (2)
0 Karma
1 Solution

Communicator

 

| rex "hostname (?<hostname>[^\s]*)"

 

View solution in original post

0 Karma

Communicator

Ah, this DID work! There was a temporary problem with our data that caused an issue. Thank you!

0 Karma

Communicator

 

| rex "hostname (?<hostname>[^\s]*)"

 

View solution in original post

0 Karma

Communicator

That didn't seem to work - no results were produced. The hostname string is within a field called "msg" if that matters (though I tried plugging that in and still can't get results).

0 Karma