Splunk Search

Regex expression Help pls ! urgent !

kailun92
Communicator

I have these fields

time : 1371877918
windBearing : 209
windSpeed : 6.34
psiAverage : 186
latitude : 1.429463
longitude : 103.835182
location : Yishun
cloudCover : 0.73
dewPoint : 69.96
humidity : 0.57
icon : partly-cloudy-day
ozone : 274.44
precipIntensity : 0
pressure : 1007.33
summary : Mostly Cloudy
temperature : 92.25

Anyone could tell me how to extract icon using regex expression ? I used this (?i)icon : (?P.+) expression but it return the bottom data also. Help pls. Thanks in advance.

1 Solution

starcher
Influencer

Try changing the .+ to [^\s\n]+

View solution in original post

starcher
Influencer

Try changing the .+ to [^\s\n]+

kailun92
Communicator

Thank you sooo much !!!!! love ya !

0 Karma

chris
Motivator

This should work:

(?i)icon : (?P<fieldname>.+)\n

kailun92
Communicator

Good job !

0 Karma

kailun92
Communicator

I tried this but it still take out the value below it.

time : 1371883969
visibility : 4.67
windBearing : 201
windSpeed : 11.6
psiAverage : 184
latitude : 1.429463
longitude : 103.835182
location : Yishun
cloudCover : 0.9
dewPoint : 63.11
humidity : 0.5
icon : wind
ozone : 273.95
precipIntensity : 0
pressure : 1006.59
summary : Breezy and Mostly Cloudy
temperature : 94.24

Such as
cloudy
ozone : 273.95
precipIntensity : 0
pressure : 1006.59
summary : Breezy and Mostly Cloudy

Any more ways that will work ?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...