Splunk Search

How to extract the user and move it to a field in Splunk?

LearningGuy
Motivator

How to extract the following user and move it to a field in Splunk?
message: xad="/home/andy"
message: xad="/home/george"
message: xad="/home/cindy"
and a lot more..
I would like to get an output as follows.    Because of the quote " before /home, Splunk rejected my regex. Please help. Thanks
user  
====    
andy
george
cindy

Labels (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

You obviously has a field named xad.  From this, no need for rex.

| eval user = mvindex(split(xad, "/"), 1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I think @yuanliu meant

| eval user = mvindex(split(xad, "/"), 2)

Having said that, can you share the failed rex and/or the full events (anonymised, of course) in a code block </> to preserve the format of the event?

0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...