Splunk Search

Need help with Rex Function

Stephen11
Explorer

I got a variable called _host_name which = usscic-secfio102.na.xxx.com.  I need to derive a variable called host_short which will have the value of usscic-secfio102   -- I use Ruby Regular expression editor to figure out expression to get string i need -- it's    ^\w+.\w+     How do I integrate in querty using rex?

 

index=cisco sourcetype=cisco_asa AND vendor_action=permitted AND host=158.11.333.444 | eval service=transport."/".dest_port| lookup dnslookup ip as host output host as host_name| rex????? | table host_short

0 Karma

Stephen11
Explorer

thanks ... that was easy

 

0 Karma

to4kawa
Ultra Champion

rex field=called _host_name "(?<short_host>[^\.]+)"
how about this?

Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...