Splunk Search

Rex 16 digit account number that always starts with 8

kmccowen
Path Finder

I using the below REX but i'm getting unwanted values for another field that is not related to account number.

REX: -\s(?<acct>\d{16})

Example Log:

[2015-06-21T23:59:53.882-05:00] [gw_server6] [NOTIFICATION] [] [com.charter.customer.care.view.backing.banner.BannerFlowBean] [tid: [ACTIVE].ExecuteThread: '2' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: cbrewster] [ecid: 8e4ec398-841d-45ad-9eb6-dec27a6d5b42-0004b72b,0] [APP: chtrgwy] 2015-06-21 23:59:53.882 - CTIPOP CALL RECEIVED - FGS - 8246100013000800- 8178750270 - 558795aa00000000ac10edf823300002

My extraction is pulling in a value of 5586441100000000 in some cases but in most cases i'm getting what I want which would be 8246100013000800

Valid account numbers should always start with the number "8" is there a way to add that logic into my existing Extraction for my Account number field?

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi kmccowen,

try something like this:

your base search here | rex field=_raw "-\s(?<acct>\d{16})\s-" | table acct

This will capture only 16 digits until the next - is found.

Hope this helps...

cheers, MuS

View solution in original post

MuS
Legend

Hi kmccowen,

try something like this:

your base search here | rex field=_raw "-\s(?<acct>\d{16})\s-" | table acct

This will capture only 16 digits until the next - is found.

Hope this helps...

cheers, MuS

kmccowen
Path Finder

need to add a white space "/s" prior to the final dash

MuS
Legend

thanks for the hint 😉

0 Karma

kmccowen
Path Finder

Final regex:

your base search here  | rex field=_raw "-\s(?<acct>\d{16})\s-"
0 Karma

kmccowen
Path Finder

I just needed to add one blank white space prior to the last "dash" and this fixed the extraction!
Thanks MuS!

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...