Splunk Search

REX - Extracting multiple fields- What's the rex syntax to return microService AND warningMessage?

Mick_OBrien
Path Finder

I have raw message of the form...

2022-08-15T10:41:54.266337+00:00 microService 9bc7520a-4f8d-4edc-a4cd-b08c0fae8992[[APP/PROC/WEB/2]] APPENDER=APP, DATE=2022-08-15 10:41:54.266, LEVEL=WARN , USER=, THREAD=[pool-25-thread-1], LOGGER=Factory, CORR=, INT_CORR=, X-VCAP-REQUEST-ID=, MESSAGE=warningMessage

What's the rex syntax to return microService AND warningMessage?

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Field names are case sensitive so microService is not the same as microservice (the name of the field in the rex extract)

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| rex "^\S+\s(?<microservice>\S+).*MESSAGE=(?<message>.+)"

https://regex101.com/r/nE14zp/1

0 Karma

Mick_OBrien
Path Finder

Tried....

index=splunkIndex "*LEVEL=WARN*" | rex "^\S+\s(?<microservice>\S+).*MESSAGE=(?<message>.+)" | table _raw, microService, message

...and I see the message but NOT the microservice

FYI the returned _raw message starts...

2022-08-15T10:53:25.650962+00:00 microService

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Field names are case sensitive so microService is not the same as microservice (the name of the field in the rex extract)

Mick_OBrien
Path Finder

Thank  you - that worked!

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...