Splunk Search
Highlighted

How to write regex for rex command to extract value after a colon?

Explorer

Hi,
Can any one help me how to display the below value which is in double quotation using rex command
API : IO ET :"2465ms"

0 Karma
Highlighted

Re: How to write regex for rex command to extract value after a colon?

Influencer
....| rex "(?i)\s\:\"(?P.*?\d+ms)\W" | table DURATION

View solution in original post

Highlighted

Re: How to write regex for rex command to extract value after a colon?

Splunk Employee
Splunk Employee
... | rex "API\s\:\sIO\sET\s\:\"(?<myvalue>\d+)ms\"" | table myvalue

That will also capture based on the text match before, leading up to the quotes, capture in the quotes up to the ms label.

0 Karma