Splunk Search

Regex generation

Deepz2612
Explorer

I have the below set of events where I wanted to write regex to capture only the last word

Kindly help

Tags (1)
0 Karma

woodcock
Esteemed Legend

Like this:

... | rex "(?<LastWord>\w+)$"
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi Deepz2612,
I don't see the set of events.
Anyway, to extract the last word od an event and put it in a field, you could use a regex like this:

| rex "\s+(?<my_field>\w+)$"

that you can test at https://regex101.com/r/hofrdl/1 .

Ciao.
Giuseppe

rmmiller
Contributor

Assuming you just want the last word in each event, this should work fine:

.+\b(\w+)$

If you want a more restrictive match, looking for only "begin" or "end", then this should work:

.+\b(begin|end)$

Hope that helps!
rmmiller

Edit: Used https://regexr.com/ to test/generate regex.

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...