Splunk Search

How to split event data?

nwoolley
Engager

Hi! In the Event column, I get the following:

26/05/2020 11:24:51 > Invoice Val Increase on History Report process completed

I have tried multiple ways to get the "Report" name as, ie:

26/05/2020 11:24:51 > Invoice Val Increase on History Report process completed

How do I split that out?

0 Karma

to4kawa
Ultra Champion
...
| rex "\> (?<report>.*?Report)"

use rex

0 Karma

nwoolley
Engager

I have tried multiple ways to get the "Report" name only ie "Invoice Val Increase on History Report" quotes not required - how do I split that out please

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...