Splunk Search

Parse a field value

simonattardGO
Path Finder

Hi,

I have a field called operationDuration. This field has a value in the form of Xms. Eg:10ms
How can I parse this value so that I remove the ms, i.e. I get only the numerical value?
I tried to do this in the Tag extraction, but regex look around does not seem to work.

Thanks a lot

Simon

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Have your tried this (assuming that the field operationDuration is already extracted);

  your_search | rex field=operationDuration "(?<OPER_DUR_NUM>\d+)ms"

The extraction above will give you a field called OPER_DUR_NUM in the fields column on the left.
You can of course call it whatever you like.


UPDATE:

In order to test whether the extraction worked correctly, you can type in the following search:

 your_search | rex field=operationDuration "(?<OPER_DUR_NUM>\d+)ms" | table operationDuration, OPER_DUR_NUM

Also, note that this is not a "permanent" field extraction - it only lives within this search. If you want to make the new field available without specifying the rex statement as part of every search query, you should make a permanent extraction, e.g. with IFX or directly in props.conf.

For more info on field extraction see:

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsatsearchtime

/Kristian

View solution in original post

imrago
Contributor

you could use:

| convert num(operationDuration)

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/convert

0 Karma

kristian_kolb
Ultra Champion

Have your tried this (assuming that the field operationDuration is already extracted);

  your_search | rex field=operationDuration "(?<OPER_DUR_NUM>\d+)ms"

The extraction above will give you a field called OPER_DUR_NUM in the fields column on the left.
You can of course call it whatever you like.


UPDATE:

In order to test whether the extraction worked correctly, you can type in the following search:

 your_search | rex field=operationDuration "(?<OPER_DUR_NUM>\d+)ms" | table operationDuration, OPER_DUR_NUM

Also, note that this is not a "permanent" field extraction - it only lives within this search. If you want to make the new field available without specifying the rex statement as part of every search query, you should make a permanent extraction, e.g. with IFX or directly in props.conf.

For more info on field extraction see:

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsatsearchtime

/Kristian

simonattardGO
Path Finder

thanks for your post kristian.

How can I view the extracted value, so that I can check if the extraction was correct?

Thanks

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...