Splunk Search

Regex for values between comma's

jacqu3sy
Path Finder

Hi,

I need a Regex to use within the search query to pick up individual values separated by comma's within a set of speech marks. The number of values varies, but is started and broken by those speech marks.

For example within the _raw I have;

db_values="value1, value2, value3, value4"

I tried the following but not sure how I separate out value 1 and value 2 etc into separate entities;

rex field=db_value"(?P\w+_\w+)-"

Thanks.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
I'm not sure to have understood your need.
if you want to extract in separate events all the values in db_value you could use something like this

your_regex
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Splunk automatically extract db_values field, if you want it's possible to extract using a regex:

your_regex
| rex max_match=0 "db_values="(?<db_values>[^,]*)"
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
I'm not sure to have understood your need.
if you want to extract in separate events all the values in db_value you could use something like this

your_regex
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Splunk automatically extract db_values field, if you want it's possible to extract using a regex:

your_regex
| rex max_match=0 "db_values="(?<db_values>[^,]*)"
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Bye.
Giuseppe

0 Karma

jacqu3sy
Path Finder

Awesome. The second one worked perfectly. thanks.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...