Splunk Search

How to remove double quotes from extracted field values

Sekhar
Explorer

Filed extracted like rex field = msg " student information\" : (?<studentname>.*?),"

 

Student name getting like below

"Stdent570"

"55555sdeend"

I want data with our double quotes 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sekhar,

if you could share some sample of your data I can be more sure.

anyway, you should try something like this:

| rex field=msg "student\s+information\"\s+:\s+\"(?<studentname>[^\"]*)"

Ciao.

Giuseppe

Sekhar
Explorer

Sample data format

{\"studenrinformation\" :  \"student577474\", }

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sekhar,

please trys this:

| rex field=msg "studentinformation\\\"\s+:\s+\\\"(?<studentname>[^\"]*)"

that you can test at https://regex101.com/r/GQVTYF/1

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...