Splunk Search

How to extract the substring from a string

febbi
Explorer

I want to extract the substring: "xenmobile" from string:  "update task to xenmobile-2021-11-08-19-created completed!", how can I get that?

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
| makeresults
| eval foo = "update task to xenmobile-2021-11-08-19-created completed!"
| rex field=foo "update task to (?<bar>[^-]+)"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| replace "xenmobile" WITH "" IN field
0 Karma

isoutamo
SplunkTrust
SplunkTrust
| makeresults
| eval foo = "update task to xenmobile-2021-11-08-19-created completed!"
| rex field=foo "update task to (?<bar>[^-]+)"
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...