Splunk Search

How to write the regex to extract data inside square brackets?

balach
New Member

How to write a regular expression for capturing elapsed time of requests, with a log in this format.
.......status=[200], time=[687 ms] ?

0 Karma
1 Solution

MuS
Legend

Hi balach,

best thing to do here is to use props.conf and transforms.conf to get this captured:

transforms.conf

 [myTransform]
 REGEX = (\w+)=\[(\d+)\]
 FORMAT = $1::$2

props.conf

[mySourceType]
REPORT-myUniqueClassName = myTransform

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi balach,

best thing to do here is to use props.conf and transforms.conf to get this captured:

transforms.conf

 [myTransform]
 REGEX = (\w+)=\[(\d+)\]
 FORMAT = $1::$2

props.conf

[mySourceType]
REPORT-myUniqueClassName = myTransform

Hope this helps ...

cheers, MuS

balach
New Member

Is there any way I can capture this without using these .conf files.

0 Karma

MuS
Legend

Sure, but it will be hard coded this way not as dynamic as the props.conf and transforms.conf approach which will pick up the first as field and the second one as value.

Try this regex:

.. | rex "status=\[(?<status>\d+)\],\stime=\[(?<time>\d+)\sms\]" | table status time
0 Karma

balach
New Member

Thanks MuS. This helps.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...