Splunk Search

Need help with syntax and rex

LizAndy123
Path Finder

I have a log with a sample of the following

POST Uploaded File Size for project id : 123 and metadata id : xxxxxxxxxxxx is : 1234 and time taken to upload is: 51ms

 

So this is project id : 123

Size is 1234

Upload Speed is 51ms

I what to extract the project id , size and the upload time as fields 

also regarding the upload time I guess I just need the number right.

 

Labels (3)
0 Karma
1 Solution

jawahir007
Communicator

Try this :

|rex "project\sid[\s\:]+(?<project_id>[^\s]+).+?is[\s\:]+(?<size>[^\s]+).+?is[\s\:]+(?<upload_time_ms>\d+)"

 

View solution in original post

LizAndy123
Path Finder

Thanks both of you - both work :-0)

0 Karma

jawahir007
Communicator

Try this :

|rex "project\sid[\s\:]+(?<project_id>[^\s]+).+?is[\s\:]+(?<size>[^\s]+).+?is[\s\:]+(?<upload_time_ms>\d+)"

 

gcusello
SplunkTrust
SplunkTrust

Hi @LizAndy123 ,

please try this:

| rex "project id : (?<Project_Id>\d+) and metadata id : \w+\sis\s:\s(?<Size>\d+) and time taken to upload is: (?<Upload_Speed>\w+)"

that you can test at project id : (?<Project_Id>\d+) and metadata id : \w+\sis\s:\s(?<Size>\d+) and time taken to upload is: (?<Upload_Speed>\w+)

Ciao.

Giuseppe

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...