Splunk Search

How to write Splunk query to extract a field from raw data?

rajs115
Path Finder

Hi,

  I am trying to find a query to extract specific code from the raw splunk data. Below is the raw content.

raw:

[demo] FATAL com.test.data - ***** Major issue error: xyz: Completion Code '1', Reason '111'

 

I need to extract the data "Major issue error:xyz". Please help to me extract it.

 

Thanks,

Raj.

Labels (4)
0 Karma
1 Solution

LRF
Path Finder

Hi @rajs115 ,

Not knowing how the complete patterns of the reported logs is, the following regex can be used as a template:

 

<your base search here> |rex field=_raw "(?<majorIssue>Major issue error:.*):\s"

 

 regex will be applied on the _raw field to capture everything specified in the capturing group and will be extracted in a new field called majorIssue

Sample Result:

_raw_timemajorIssue
[demo] FATAL com.test.data - ***** Major issue error: xyz: Completion Code '1', Reason '111'2023-03-29 19:40:49Major issue error: xyz

 

Sample Spl query:

|makeresults |eval _raw="[demo] FATAL com.test.data - ***** Major issue error: xyz: Completion Code '1', Reason '111'" |rex field=_raw "(?<majorIssue>Major issue error:.*):\s"

 

Hope this will help you, have a nice day!

Fabrizio 

View solution in original post

0 Karma

LRF
Path Finder

Hi @rajs115 ,

Not knowing how the complete patterns of the reported logs is, the following regex can be used as a template:

 

<your base search here> |rex field=_raw "(?<majorIssue>Major issue error:.*):\s"

 

 regex will be applied on the _raw field to capture everything specified in the capturing group and will be extracted in a new field called majorIssue

Sample Result:

_raw_timemajorIssue
[demo] FATAL com.test.data - ***** Major issue error: xyz: Completion Code '1', Reason '111'2023-03-29 19:40:49Major issue error: xyz

 

Sample Spl query:

|makeresults |eval _raw="[demo] FATAL com.test.data - ***** Major issue error: xyz: Completion Code '1', Reason '111'" |rex field=_raw "(?<majorIssue>Major issue error:.*):\s"

 

Hope this will help you, have a nice day!

Fabrizio 

0 Karma

rajs115
Path Finder

hi @LRF , thanks for your response. it worked

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...