Splunk Search

How to extract using rex

avi7326
Path Finder

 I want to extract the below contractWithCustomers and  contracts  using rex named as entity . 
For ID 1349c1f4-989c-4ea5-94ca-25fc40f6aab8 -flow started put:\contractWithCustomers:application\json:bmw-crm-wh-xl-cms-api-config

For ID 1697108895 -flow started put:\contracts:application\json:bmw-crm-wh-xl-cms-api-config

avi7326_0-1698331179533.png

 



 

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex "put:\\\\(?<Entity>[^:]+)"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

What would the expected output look like?

0 Karma

avi7326
Path Finder

In table want a field name as -
Entity 
contractWithCustomers
contracts

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "put:\\\\(?<Entity>[^:]+)"
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...