Splunk Search

Regex for values between comma's

jacqu3sy
Path Finder

Hi,

I need a Regex to use within the search query to pick up individual values separated by comma's within a set of speech marks. The number of values varies, but is started and broken by those speech marks.

For example within the _raw I have;

db_values="value1, value2, value3, value4"

I tried the following but not sure how I separate out value 1 and value 2 etc into separate entities;

rex field=db_value"(?P\w+_\w+)-"

Thanks.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
I'm not sure to have understood your need.
if you want to extract in separate events all the values in db_value you could use something like this

your_regex
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Splunk automatically extract db_values field, if you want it's possible to extract using a regex:

your_regex
| rex max_match=0 "db_values="(?<db_values>[^,]*)"
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
I'm not sure to have understood your need.
if you want to extract in separate events all the values in db_value you could use something like this

your_regex
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Splunk automatically extract db_values field, if you want it's possible to extract using a regex:

your_regex
| rex max_match=0 "db_values="(?<db_values>[^,]*)"
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Bye.
Giuseppe

0 Karma

jacqu3sy
Path Finder

Awesome. The second one worked perfectly. thanks.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...