Splunk Search

Rex formatting trouble

MikeB
Path Finder

Hello again Spelunkers! 

So I have data that looks like this:

assessment=normal [1.0]
assessment=normal [1.1]
assessment=suspect [0.75]
assessment=suspect [0.88]
assessment=bad [0.467]


I want a table column named rating that takes the "normal," "suspect," "bad" without the [###] after it. So I wrote the below thinking I can name the column rating and then capture any alpha characters and terminate at the white space between the word value and the [###] value. What would be the correct way of writing this? Thank you in advance!

 

| rex field=raw_ "assessment=(?<rating>/\w/\s)"

 



Labels (1)
Tags (3)
0 Karma
1 Solution

danielcj
Communicator

Hi,

 

Please, try the following:

| rex field=_raw "assessment=(?<rating>\S+)"



View solution in original post

0 Karma

danielcj
Communicator

Hi,

 

Please, try the following:

| rex field=_raw "assessment=(?<rating>\S+)"



0 Karma

MikeB
Path Finder

Thank you! This worked perfectly. 

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...