Splunk Search

How to fetch the second last word of a sentence with the Splunk regex?

riginoommen
Explorer

My query is:

 

Mozilla/5.0 (X11; Linux x86_64; Catchpoint) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36

 

I want to extract the following word from the above sting with regex can you please help me.

 

Chrome/87.0.4280.88

 

Labels (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Try like this (replace everything before "rex" command with your search)

|makeresults | eval _raw="Mozilla/5.0 (X11; Linux x86_64; Catchpoint) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" | table _raw 
| rex "\s+(?<SecondLastPart>\S+)\s+\S+$"

  

View solution in original post

somesoni2
Revered Legend

Try like this (replace everything before "rex" command with your search)

|makeresults | eval _raw="Mozilla/5.0 (X11; Linux x86_64; Catchpoint) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" | table _raw 
| rex "\s+(?<SecondLastPart>\S+)\s+\S+$"

  

riginoommen
Explorer

This fetched the data as expected but its not taking the filtered data from past output

0 Karma

riginoommen
Explorer

Can you please see the updated question

0 Karma

Stefanie
Builder

Sure

Try this one?

 

\s\S+\/\S+\s(?!\()
0 Karma

Stefanie
Builder

Hi!

Try this Regex.

 

\b(\S+)$

riginoommen
Explorer

How to use the regex with the rex tag

\b(\S+)$
can you please help me
 
0 Karma

riginoommen
Explorer

Can you please see the updated question with the answer and I am trying to accommodate with the res. it will be super awesome if you share the full url

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...