Splunk Search

Regex expression Help pls ! urgent !

kailun92
Communicator

I have these fields

time : 1371877918
windBearing : 209
windSpeed : 6.34
psiAverage : 186
latitude : 1.429463
longitude : 103.835182
location : Yishun
cloudCover : 0.73
dewPoint : 69.96
humidity : 0.57
icon : partly-cloudy-day
ozone : 274.44
precipIntensity : 0
pressure : 1007.33
summary : Mostly Cloudy
temperature : 92.25

Anyone could tell me how to extract icon using regex expression ? I used this (?i)icon : (?P.+) expression but it return the bottom data also. Help pls. Thanks in advance.

1 Solution

starcher
Influencer

Try changing the .+ to [^\s\n]+

View solution in original post

starcher
Influencer

Try changing the .+ to [^\s\n]+

kailun92
Communicator

Thank you sooo much !!!!! love ya !

0 Karma

chris
Motivator

This should work:

(?i)icon : (?P<fieldname>.+)\n

kailun92
Communicator

Good job !

0 Karma

kailun92
Communicator

I tried this but it still take out the value below it.

time : 1371883969
visibility : 4.67
windBearing : 201
windSpeed : 11.6
psiAverage : 184
latitude : 1.429463
longitude : 103.835182
location : Yishun
cloudCover : 0.9
dewPoint : 63.11
humidity : 0.5
icon : wind
ozone : 273.95
precipIntensity : 0
pressure : 1006.59
summary : Breezy and Mostly Cloudy
temperature : 94.24

Such as
cloudy
ozone : 273.95
precipIntensity : 0
pressure : 1006.59
summary : Breezy and Mostly Cloudy

Any more ways that will work ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...