Splunk Search

How to extract value with in brackets

kavyatim
Path Finder

Hi ,
I have data in the following format:
NOT_HOMOLOGATED-(UNKNOWN)
HOMOLOGATED-(Thomson SpeedTouch ST510 V6 versao 6.2.15.7 or ST585 v6)
NOT_HOMOLOGATED-(UNKNOWN)
HOMOLOGATED-(ZTE ZXDSL 831 II V7.5.02_E09_BR1)
NOT_HOMOLOGATED-(UNKNOWN)
NOT_HOMOLOGATED-(UNKNOWN)
HOMOLOGATED-(ZTE ZXDSL 831 II V7.5.02_E09_BR1)
HOMOLOGATED-(Thomson SpeedTouch ST510 V6 versao 6.2.15.7 or ST585 v6)
I would like to extract value with in the brackets i.e extracted values should be:
UNKNOWN
Thomson SpeedTouch ST510 V6 versao 6.2.15.7 or ST585 v6
UNKNOWN
ZTE ZXDSL 831 II V7.5.02_E09_BR1
and so on . . . . .

Can any one help me out in writing regex for this as it is not flexible with substring?

Thanking you in advance.

Tags (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi kavyatim,

something like

YourFancySearch | rex "\((?<myField>.*)\)" 

should work fine for you.
Here is a link to a page were you can test regex on your data.

hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi kavyatim,

something like

YourFancySearch | rex "\((?<myField>.*)\)" 

should work fine for you.
Here is a link to a page were you can test regex on your data.

hope this helps ...

cheers, MuS

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...