Splunk Search

Return string and number before and after equals sign

soumyajk
Engager

Hi,

I am new in splunk and i want to save the value in fields before and after =

for example events look like below
rollnumber=34556
class=12

I want to return rollnumber and class in first field and the number after = in second field.

base search | rex max_match=15 field=_raw "(?P)="

this doesnt work, both values are coming as space.

0 Karma
1 Solution

damien_chillet
Builder

Your regex seems to be incomplete, could you try:

| rex max_match=15 field=_raw "(?P<field1>\w+)\=(?P<field2>\w+)" 

View solution in original post

damien_chillet
Builder

Your regex seems to be incomplete, could you try:

| rex max_match=15 field=_raw "(?P<field1>\w+)\=(?P<field2>\w+)" 
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...