Splunk Search

How to extract the user and move it to a field in Splunk?

LearningGuy
Builder

How to extract the following user and move it to a field in Splunk?
message: xad="/home/andy"
message: xad="/home/george"
message: xad="/home/cindy"
and a lot more..
I would like to get an output as follows.    Because of the quote " before /home, Splunk rejected my regex. Please help. Thanks
user  
====    
andy
george
cindy

Labels (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

You obviously has a field named xad.  From this, no need for rex.

| eval user = mvindex(split(xad, "/"), 1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I think @yuanliu meant

| eval user = mvindex(split(xad, "/"), 2)

Having said that, can you share the failed rex and/or the full events (anonymised, of course) in a code block </> to preserve the format of the event?

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...