Splunk Search

How to write the regex to extract data inside square brackets?

balach
New Member

How to write a regular expression for capturing elapsed time of requests, with a log in this format.
.......status=[200], time=[687 ms] ?

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi balach,

best thing to do here is to use props.conf and transforms.conf to get this captured:

transforms.conf

 [myTransform]
 REGEX = (\w+)=\[(\d+)\]
 FORMAT = $1::$2

props.conf

[mySourceType]
REPORT-myUniqueClassName = myTransform

Hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi balach,

best thing to do here is to use props.conf and transforms.conf to get this captured:

transforms.conf

 [myTransform]
 REGEX = (\w+)=\[(\d+)\]
 FORMAT = $1::$2

props.conf

[mySourceType]
REPORT-myUniqueClassName = myTransform

Hope this helps ...

cheers, MuS

balach
New Member

Is there any way I can capture this without using these .conf files.

0 Karma

MuS
SplunkTrust
SplunkTrust

Sure, but it will be hard coded this way not as dynamic as the props.conf and transforms.conf approach which will pick up the first as field and the second one as value.

Try this regex:

.. | rex "status=\[(?<status>\d+)\],\stime=\[(?<time>\d+)\sms\]" | table status time
0 Karma

balach
New Member

Thanks MuS. This helps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...