Splunk Search

Regex generation

Deepz2612
Explorer

I have the below set of events where I wanted to write regex to capture only the last word

Kindly help

Tags (1)
0 Karma

woodcock
Esteemed Legend

Like this:

... | rex "(?<LastWord>\w+)$"
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi Deepz2612,
I don't see the set of events.
Anyway, to extract the last word od an event and put it in a field, you could use a regex like this:

| rex "\s+(?<my_field>\w+)$"

that you can test at https://regex101.com/r/hofrdl/1 .

Ciao.
Giuseppe

rmmiller
Contributor

Assuming you just want the last word in each event, this should work fine:

.+\b(\w+)$

If you want a more restrictive match, looking for only "begin" or "end", then this should work:

.+\b(begin|end)$

Hope that helps!
rmmiller

Edit: Used https://regexr.com/ to test/generate regex.

0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...