Splunk Search

Need help with syntax and rex

LizAndy123
Path Finder

I have a log with a sample of the following

POST Uploaded File Size for project id : 123 and metadata id : xxxxxxxxxxxx is : 1234 and time taken to upload is: 51ms

 

So this is project id : 123

Size is 1234

Upload Speed is 51ms

I what to extract the project id , size and the upload time as fields 

also regarding the upload time I guess I just need the number right.

 

Labels (3)
0 Karma
1 Solution

Jawahir
Communicator

Try this :

|rex "project\sid[\s\:]+(?<project_id>[^\s]+).+?is[\s\:]+(?<size>[^\s]+).+?is[\s\:]+(?<upload_time_ms>\d+)"

 

View solution in original post

LizAndy123
Path Finder

Thanks both of you - both work :-0)

0 Karma

Jawahir
Communicator

Try this :

|rex "project\sid[\s\:]+(?<project_id>[^\s]+).+?is[\s\:]+(?<size>[^\s]+).+?is[\s\:]+(?<upload_time_ms>\d+)"

 

gcusello
SplunkTrust
SplunkTrust

Hi @LizAndy123 ,

please try this:

| rex "project id : (?<Project_Id>\d+) and metadata id : \w+\sis\s:\s(?<Size>\d+) and time taken to upload is: (?<Upload_Speed>\w+)"

that you can test at project id : (?<Project_Id>\d+) and metadata id : \w+\sis\s:\s(?<Size>\d+) and time taken to upload is: (?<Upload_Speed>\w+)

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

test 2

test 222222

test

test

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...