Splunk Search

Rex command help

mpk_24
Explorer

Hey @Splunkers,

Looking for valuable insights for this use case.

 

I wanted to extract the numbers at the end of the log (highlighted in bold). Pls help.

Sample log:

74.133.120.000 - LASTHOP:142.136.168.1 - [19/May/2025:23:30:12 +0000] "GET /content/*/residential.existingCustomerProfileLoader.json HTTP/1.1" 200 143 "/cp/activate-apps?cmp=dotcom_sms_selectapps_111324" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36" 384622

Labels (1)
0 Karma
1 Solution

liangliang
Explorer

you can try this   (?P<number>\d+)$  
the $ will match the end of this line

View solution in original post

mpk_24
Explorer

@liangliang thank you so much for your respond. This works. Appreciate very much.  

0 Karma

liangliang
Explorer

you can try this   (?P<number>\d+)$  
the $ will match the end of this line

Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...