Splunk Search

How to split event data?

nwoolley
Engager

Hi! In the Event column, I get the following:

26/05/2020 11:24:51 > Invoice Val Increase on History Report process completed

I have tried multiple ways to get the "Report" name as, ie:

26/05/2020 11:24:51 > Invoice Val Increase on History Report process completed

How do I split that out?

0 Karma

to4kawa
Ultra Champion
...
| rex "\> (?<report>.*?Report)"

use rex

0 Karma

nwoolley
Engager

I have tried multiple ways to get the "Report" name only ie "Invoice Val Increase on History Report" quotes not required - how do I split that out please

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...