Splunk Search

How to trim information from search output?

jugarugabi
Path Finder

Hi, 

I am having the following query: 

index=* sourcetype=CustomAccessLog | table "host", "source"

 

The output is:

host source
server32.de.db.com /path/to/server/instances/IFM_RT_1/logs/subdir_logs/log.file
server31.de.db.com /path/to/server/instances/IFM_RT_2/logs/subdir_logs/log.file

 

I would need to alter the search query so that the output is becoming:

host source
32 IFM_RT_1
31 IFM_RT_2

 

Tried using the following for the IFM_RT_

index=* sourcetype=CustomAccessLog | rex field=_raw "(?<IFM_RT_>.*)", but I couldn't get the needed data. 

Can I have your help here?

 

Thanks!

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jugarugabi,

you could try to use the following regexes:

index=* sourcetype=CustomAccessLog 
| rex field=source "(?<source>IFM_RT_\d*)"
| rex field=host "^server(?<host>\d+)"
| table host source

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jugarugabi,

you could try to use the following regexes:

index=* sourcetype=CustomAccessLog 
| rex field=source "(?<source>IFM_RT_\d*)"
| rex field=host "^server(?<host>\d+)"
| table host source

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jugarugabi,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...