Splunk Search

How to extract value using rex?

ivana27
Path Finder

Hello,

please, can you tell me how transform and extract value Timeout from next log:

[Error] POS Card Validation - Result: Timeout

using rex?

Thanks a bunch

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "Result:\s(?<result>\w+)"
0 Karma

ivana27
Path Finder

Thank you, but problem is that i have other similiar events with Result so i need to specify exactly with this sintax.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "Result:\s(?<timeout>Timeout)"

Is this what you mean? Or can you provide examples of other events that you don't want to match?

0 Karma

ivana27
Path Finder

To be transormed in something like this (i am really new with rex sintax)

| rex field=_raw "\sPOS\sStart\sCardType\:\s(?<CardType>\w+)\,\sTransactionType\:\s(?<TxType>\w+)\,\s"

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "\[Error\]\sPOS\sCard\sValidation\s\-\sResult:\s(?<timeout>Timeout)"
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...