Hi,
I have below splunk command:
| makeresults
| eval _raw="The first value is 0.00 and The second value is 0\",\"origin\":\"rep\",\"source_instance\":\"0\""
| rex "The\sfirst\svalue\sis (?<from>.*) and\sThe\ssecond\svalue\sis (?<to>.*)"
This shows the "from" field as 0.00 and "to" field as 0","origin":"rep","source_instance":"0"
In the "to" field I only want the value 0. How do I achieve that?
@sasank Test your regex in a regex editor like
https://regex101.com/r/1oqLAF/3
If you follow the link you will find your test string and a regex that you can use to match the correct values.
Thanks for the link. I couldn't figure out how to match the 2nd value so I am looking if someone can help in fixing the regex
| makeresults
| eval _raw="The first value is 0.00 and The second value is 0\",\"origin\":\"rep\",\"source_instance\":\"0\""
| rex "The\sfirst\svalue\sis (?<from>[^\s]+).+?(?<to>\d)"
@sasank Test your regex in a regex editor like
https://regex101.com/r/1oqLAF/3
If you follow the link you will find your test string and a regex that you can use to match the correct values.