Splunk Search

Regex to match the price amount in Splunk?

pavanae
Builder

The following are my search results

<Total_Amount_Due>122.34</Total_Amount_Due>
<Total_Amount_Due>2.3</Total_Amount_Due>
<Total_Amount_Due>765.33</Total_Amount_Due>

Now Please suggest me a Regex which displays all the amounts.

Thanks in Advance

0 Karma
1 Solution

somesoni2
Revered Legend

Try this (may need to adjust the

your current search giving above result | rex field=_raw "\<Total_Amount_Due\>(?<Amount[^\<]+)\<\/Total_Amount_Due\>" 

View solution in original post

ppablo
Retired

Hi @pavanae

I'm glad you've been very active here on Answers and have been getting a lot of help from the community, but I also have noticed that you've been posting a lot of question asking for users to just give you regular expressions for your sample data. Have you been trying to write your regular expressions on your own as well? I'd highly recommend you check out this previous Answers post on the various free regex resources you can look into http://answers.splunk.com/answers/153171/is-there-any-online-regex-tool-to-create-regular-e.html Just a reminder that this is a Q&A forum for Splunk specific topics and not just a place to get regular expressions written for you.

0 Karma

pavanae
Builder

ok Thanks 🙂

0 Karma

somesoni2
Revered Legend

Try this (may need to adjust the

your current search giving above result | rex field=_raw "\<Total_Amount_Due\>(?<Amount[^\<]+)\<\/Total_Amount_Due\>" 
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...