Splunk Search

Need help with syntax and rex

LizAndy123
Path Finder

I have a log with a sample of the following

POST Uploaded File Size for project id : 123 and metadata id : xxxxxxxxxxxx is : 1234 and time taken to upload is: 51ms

 

So this is project id : 123

Size is 1234

Upload Speed is 51ms

I what to extract the project id , size and the upload time as fields 

also regarding the upload time I guess I just need the number right.

 

Labels (3)
0 Karma
1 Solution

Jawahir
Communicator

Try this :

|rex "project\sid[\s\:]+(?<project_id>[^\s]+).+?is[\s\:]+(?<size>[^\s]+).+?is[\s\:]+(?<upload_time_ms>\d+)"

 

View solution in original post

LizAndy123
Path Finder

Thanks both of you - both work :-0)

0 Karma

Jawahir
Communicator

Try this :

|rex "project\sid[\s\:]+(?<project_id>[^\s]+).+?is[\s\:]+(?<size>[^\s]+).+?is[\s\:]+(?<upload_time_ms>\d+)"

 

gcusello
SplunkTrust
SplunkTrust

Hi @LizAndy123 ,

please try this:

| rex "project id : (?<Project_Id>\d+) and metadata id : \w+\sis\s:\s(?<Size>\d+) and time taken to upload is: (?<Upload_Speed>\w+)"

that you can test at project id : (?<Project_Id>\d+) and metadata id : \w+\sis\s:\s(?<Size>\d+) and time taken to upload is: (?<Upload_Speed>\w+)

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...

Application management with Targeted Application Install for Victoria Experience

Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...