Splunk Search

Regex- Help with extracting field

Dayalss
Engager

Can someone please help me in extracting the field Specific_DL_Testing from the below sample log.

instance of the "\Specific_DL_Testing" task.

The output should be Specific_DL_Testing

Labels (1)
0 Karma

Dayalss
Engager

I have used the above expression but its not extracting the field.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Here is a runanywhere example of it working

| makeresults 
| eval _raw="instance of the \"\\Specific_DL_Testing\" task." 
| rex "instance of the \"\\\(?<task>[^\"]+)\" task."

If it is not working for you, please provide example events and the SPL you are using (preferably in code blocks </> like the example above to prevent information being lost due to formatting

0 Karma

Dayalss
Engager

Task Scheduler terminated "{8878FDRGSGS-8cde-1234-123456789}" instance of the "\Specific_DL_Testing" task.

 

Please try on this event

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults 
| eval _raw="Task Scheduler terminated \"{8878FDRGSGS-8cde-1234-123456789}\" instance of the \"\\Specific_DL_Testing\" task." 
| rex "instance of the \"\\\(?<task>[^\"]+)\" task."
0 Karma

Dayalss
Engager

 I see you are checking for "\\Specific_DL_Testing\"

 Can you try for "\Specific_DL_Testing\" 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I am not checking for "\\Specific_DL_Testing\" - this is part of the eval command to create the sample _raw field in line with what you say is your event

ITWhisperer_0-1679565726287.png

As you can see from the _raw field in the screenshot, the event matches what you said you event was.

 

0 Karma

Dayalss
Engager

Getting error :- Error in 'rex' command: Encountered the following error while compiling the regex '\instance of the "\(?<task>[^"]+)" task.': Regex: unrecognized character follows \.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I missed a backslash

| rex "instance of the \"\\\(?<task>[^\"]+)\" task."
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "instance of the \"\\(?<task>[^\"]+)\" task."
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...