Splunk Search

How to extract the userID?

tankhanandita
Explorer

Hi

I want to extract the unique user ID for the users that are successfully logging in the KTB system

[2/11/00 12:45:35:039 ISTT] 00000115 SystemOut O User Login to KTB Successful - Bhatur- NT-000-TTT - PT-P065-APT
[2/11/00  9:27:26:877 ISTT] 00001309 SystemOut O User Login to KTB Successful - Bhatur- AM1353P - STYLE P Harry

Output should be:

NT-000-TTT

AM1353P

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "User Login to KTB Successful\s-\s[^\-]+\-\s(?<user>\S+)"
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...