Splunk Search

Regex for values between comma's

jacqu3sy
Path Finder

Hi,

I need a Regex to use within the search query to pick up individual values separated by comma's within a set of speech marks. The number of values varies, but is started and broken by those speech marks.

For example within the _raw I have;

db_values="value1, value2, value3, value4"

I tried the following but not sure how I separate out value 1 and value 2 etc into separate entities;

rex field=db_value"(?P\w+_\w+)-"

Thanks.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
I'm not sure to have understood your need.
if you want to extract in separate events all the values in db_value you could use something like this

your_regex
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Splunk automatically extract db_values field, if you want it's possible to extract using a regex:

your_regex
| rex max_match=0 "db_values="(?<db_values>[^,]*)"
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi jacqu3sy,
I'm not sure to have understood your need.
if you want to extract in separate events all the values in db_value you could use something like this

your_regex
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Splunk automatically extract db_values field, if you want it's possible to extract using a regex:

your_regex
| rex max_match=0 "db_values="(?<db_values>[^,]*)"
| makemv db_values delim="," 
| mvexpand db_values 
| table db_values

Bye.
Giuseppe

0 Karma

jacqu3sy
Path Finder

Awesome. The second one worked perfectly. thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...