Splunk Search

Rex formatting trouble

MikeB
Path Finder

Hello again Spelunkers! 

So I have data that looks like this:

assessment=normal [1.0]
assessment=normal [1.1]
assessment=suspect [0.75]
assessment=suspect [0.88]
assessment=bad [0.467]


I want a table column named rating that takes the "normal," "suspect," "bad" without the [###] after it. So I wrote the below thinking I can name the column rating and then capture any alpha characters and terminate at the white space between the word value and the [###] value. What would be the correct way of writing this? Thank you in advance!

 

| rex field=raw_ "assessment=(?<rating>/\w/\s)"

 



Labels (1)
Tags (3)
0 Karma
1 Solution

danielcj
Communicator

Hi,

 

Please, try the following:

| rex field=_raw "assessment=(?<rating>\S+)"



View solution in original post

0 Karma

danielcj
Communicator

Hi,

 

Please, try the following:

| rex field=_raw "assessment=(?<rating>\S+)"



0 Karma

MikeB
Path Finder

Thank you! This worked perfectly. 

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...