- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
kc_prane
Communicator
07-22-2024
07:58 PM
My Raw log says "message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc)"
I wanted to extract everything inside the Parentheses ( )
Thanks in advance.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yuanliu

SplunkTrust
07-22-2024
09:23 PM
Like this?
| rex "message: \((?<in_parentheseses>[^\)]+)"
You can test with
| makeresults format=csv data="_raw
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc)"
``` data emulation above ```
| rex "message: \((?<in_parentheses>[^\)]+)"
_raw | in_parentheses |
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc) | c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc |
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
kc_prane
Communicator
07-29-2024
08:49 AM
Thank you for the help @yuanliu
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yuanliu

SplunkTrust
07-22-2024
09:23 PM
Like this?
| rex "message: \((?<in_parentheseses>[^\)]+)"
You can test with
| makeresults format=csv data="_raw
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc)"
``` data emulation above ```
| rex "message: \((?<in_parentheses>[^\)]+)"
_raw | in_parentheses |
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc) | c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc |
