Splunk Search

Regex to extract parts of a string delimited by dost (.)

cindygibbs_08
Communicator

Hello my loves I have one quick question

 

Lets say I have this two strings

AUJ.UEIEJ.829839.239383

033.4788383.27383.8HJJJ

WHat would be the correct regex expression to extract ONLY string of characters after the first dot and before the second dot.. that means

from AUJ.UEIEJ.829839.239383 I want  UEIEJ
from 033.4788383.27383.8HJJJ I want   4788383

Thank you my loves for the help!

kindly,

C

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "^[\.]+\.(?<string>[^\.]+)\."

venkatasri
SplunkTrust
SplunkTrust

Hi @cindygibbs_08 

Can you try this?

| makeresults 
| eval x="AUJ.UEIEJ.829839.239383" 
| rex field=x "\.(?<field1>.+?)\."

---

An upvote would be appreciated if this reply helps and Accept the solution!

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@cindygibbs_08  Assumed your field name as x (replace with your field name) which containing a string value. If the string is part of _raw event and not been extracted already this might not work.

 

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...