Splunk Search

Regex to extract status[number] alone from extracted field

Bhuavana
Explorer

Hi,

I have two below field[rstatus] values extracted from events

response.status = 200
response.status = 404

Can you share the regex to extract number[i.e 200 or 404 alone ] from above string.

Tags (2)
0 Karma
1 Solution

gfuente
Motivator

Hello

try this regex:

...| rex field="rstatus" "response\.status\s\=\s(?<yourfield>\d+)" | ...

Regards

View solution in original post

0 Karma

gfuente
Motivator

Hello

try this regex:

...| rex field="rstatus" "response\.status\s\=\s(?<yourfield>\d+)" | ...

Regards

0 Karma

Bhuavana
Explorer

Thanks a lot.. above solution is worked...

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...