Splunk Search

How to extract value with in brackets

kavyatim
Path Finder

Hi ,
I have data in the following format:
NOT_HOMOLOGATED-(UNKNOWN)
HOMOLOGATED-(Thomson SpeedTouch ST510 V6 versao 6.2.15.7 or ST585 v6)
NOT_HOMOLOGATED-(UNKNOWN)
HOMOLOGATED-(ZTE ZXDSL 831 II V7.5.02_E09_BR1)
NOT_HOMOLOGATED-(UNKNOWN)
NOT_HOMOLOGATED-(UNKNOWN)
HOMOLOGATED-(ZTE ZXDSL 831 II V7.5.02_E09_BR1)
HOMOLOGATED-(Thomson SpeedTouch ST510 V6 versao 6.2.15.7 or ST585 v6)
I would like to extract value with in the brackets i.e extracted values should be:
UNKNOWN
Thomson SpeedTouch ST510 V6 versao 6.2.15.7 or ST585 v6
UNKNOWN
ZTE ZXDSL 831 II V7.5.02_E09_BR1
and so on . . . . .

Can any one help me out in writing regex for this as it is not flexible with substring?

Thanking you in advance.

Tags (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi kavyatim,

something like

YourFancySearch | rex "\((?<myField>.*)\)" 

should work fine for you.
Here is a link to a page were you can test regex on your data.

hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi kavyatim,

something like

YourFancySearch | rex "\((?<myField>.*)\)" 

should work fine for you.
Here is a link to a page were you can test regex on your data.

hope this helps ...

cheers, MuS

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...