Splunk Search

Regex for field extraction with or without comma

magriii
Explorer

I found that the format of a sourcetype had changed some time ago.
Now I need to extract the data correctly for both cases.

 

2022-01-11 17:40:59.000, SEVERITY="123", DESCRIPTION="ooops"
2018-01-24 16:35:05 SEVERITY="112", DESCRIPTION="blabla"

 

Extraction for the first type of entries works with this regex that was build with splunk field extraction

 

^(?P<dt>[^,]+)[^"\n]*"(?P<SEVERITY>\d+)[^=\n]*="(?P<DESCRIPTION>[^"]+)

 

How can the regex be expanded to split either at "," or at the second space, if the comma is missing?

An idea is to capture always at the second space and remove the comma or split before SEVERITY and remove the comma. I didn't get either working.

You can find the regex at https://regex101.com/r/mxdAyx/1 

Thanks

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
^(?P<dt>[^ ]+ [^ ,]+)[^"\n]*"(?P<SEVERITY>\d+)[^=\n]*="(?P<DESCRIPTION>[^"]+)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...