Splunk Search

Look at value ahead of string and table it

ekucevic
Loves-to-Learn Everything

I have events in my logs. I want to capture "temp" and table it
received_time="2021-05-25T15:51:22.181+00:00"] 37 pollAcu20:830 ACU: PSU: Connected: true Output voltage: 4775 0.01V, Output current: 36 0.01A Critical temp: 426 0.1 Deg C Status: 0x3 Fault: false

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

As suggested by the "rex" label, the rex command can help.

... | rex "Critical temp: (?<temp>.*?) Deg"
| table temp
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...