Splunk Search

How to extract the new field into interesting field from raw event?

Nagalakshmi
Path Finder

Hi Team,

we are trying to add new field  as a display name into interesting field from below raw event




DisplayName: sample-Hostname

We tried the below query but it is not working 

| rex field=_raw \"DisplayName", "Value":\s(?<DisplayName>\w+).

And also please suggest us how to create a query if the user logged in one or more devices.

Thanks in advance!

Labels (2)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Nagalakshmi ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

Nagalakshmi
Path Finder

Hi @gcusello ,

Thanks for the quick response!

The above query is perfectly working


0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nagalakshmi ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

gcusello
SplunkTrust
SplunkTrust

Hi @Nagalakshmi ,

this seems to be a json log, so you can extract all fields using the "INDEXED_EXTRACTION = json" in the props.conf or using the "spath" command.

If you want to use a regex, you can use:

| rex "DisplayName\",\s+\"Value\":\s+\"(?<DisplayName>[^\"]+)"

that you can test at https://regex101.com/r/hjQXGU/1

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...