Splunk Search

How to write the regex to extract data inside square brackets?

balach
New Member

How to write a regular expression for capturing elapsed time of requests, with a log in this format.
.......status=[200], time=[687 ms] ?

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi balach,

best thing to do here is to use props.conf and transforms.conf to get this captured:

transforms.conf

 [myTransform]
 REGEX = (\w+)=\[(\d+)\]
 FORMAT = $1::$2

props.conf

[mySourceType]
REPORT-myUniqueClassName = myTransform

Hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi balach,

best thing to do here is to use props.conf and transforms.conf to get this captured:

transforms.conf

 [myTransform]
 REGEX = (\w+)=\[(\d+)\]
 FORMAT = $1::$2

props.conf

[mySourceType]
REPORT-myUniqueClassName = myTransform

Hope this helps ...

cheers, MuS

balach
New Member

Is there any way I can capture this without using these .conf files.

0 Karma

MuS
SplunkTrust
SplunkTrust

Sure, but it will be hard coded this way not as dynamic as the props.conf and transforms.conf approach which will pick up the first as field and the second one as value.

Try this regex:

.. | rex "status=\[(?<status>\d+)\],\stime=\[(?<time>\d+)\sms\]" | table status time
0 Karma

balach
New Member

Thanks MuS. This helps.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...