Splunk Search

Splunk Regex Field Extractions

franciscoz1
Engager

When writing regex, where in the regex string am I supposed to add the (?<new_field>) string ?

I have included a sample regex string below, where in this string would I add (?<new_field>) ?

(?<=\:\[)(.*)(?=\])

Thanks !

Labels (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

If that is the exact regex and you are talking about using the rex command, then 

 

| rex "(?<new_field>(?<=\:\[)(.*)(?=\]))"

 

will extract the data between the [] into new_field

View solution in original post

franciscoz1
Engager

Worked like a charm, thank you !

0 Karma

bowesmana
SplunkTrust
SplunkTrust

If that is the exact regex and you are talking about using the rex command, then 

 

| rex "(?<new_field>(?<=\:\[)(.*)(?=\]))"

 

will extract the data between the [] into new_field

Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...