Splunk Search

Regex to extract status[number] alone from extracted field

Bhuavana
Explorer

Hi,

I have two below field[rstatus] values extracted from events

response.status = 200
response.status = 404

Can you share the regex to extract number[i.e 200 or 404 alone ] from above string.

Tags (2)
0 Karma
1 Solution

gfuente
Motivator

Hello

try this regex:

...| rex field="rstatus" "response\.status\s\=\s(?<yourfield>\d+)" | ...

Regards

View solution in original post

0 Karma

gfuente
Motivator

Hello

try this regex:

...| rex field="rstatus" "response\.status\s\=\s(?<yourfield>\d+)" | ...

Regards

0 Karma

Bhuavana
Explorer

Thanks a lot.. above solution is worked...

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...