Splunk Search

Single line of regex to extract multiple fields

token1
Explorer

I've seen the TA Unified2 do this, one single line of regex pulling all relevant fields from snort logs.  I'm wanting to do the same thing for some NetApp logs I have:

The regex101 URL is:  https://regex101.com/r/zlhxN9/1/

It has pretty good test data.  The first line is a very typical format.  The second line has a doozy, when an operation is carried out there is a field between the "::" delimitators that is further broken up with "<>" delimitators. 

I'm at a loss here as you can see in the regex101 URL.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I am not sure what the question is here. Please can you explain further?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...