Splunk Search

How to extract the user and move it to a field in Splunk?

LearningGuy
Builder

How to extract the following user and move it to a field in Splunk?
message: xad="/home/andy"
message: xad="/home/george"
message: xad="/home/cindy"
and a lot more..
I would like to get an output as follows.    Because of the quote " before /home, Splunk rejected my regex. Please help. Thanks
user  
====    
andy
george
cindy

Labels (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

You obviously has a field named xad.  From this, no need for rex.

| eval user = mvindex(split(xad, "/"), 1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I think @yuanliu meant

| eval user = mvindex(split(xad, "/"), 2)

Having said that, can you share the failed rex and/or the full events (anonymised, of course) in a code block </> to preserve the format of the event?

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...