Splunk Search

Splunk Regex for Field Extraction

harish0557
Explorer

I want to extract fields from the below string(JSON) for:

eval time for each javascript (i.e require.min.js)
Load time for each javascript (i.e require.min.js)

Sample data:

"date":"2014-09-14T18:39:45.170Z","level":"INFO","logger":"marker.RESTART","seq":2,"msg":{"message":"load time in milliseconds","data":[{"moduleName":"node_modules/requirejs/require.min.js","startTimestamp":1442255975613,"fileSize":15330,"loadTime":752,"evalTime":27},{"moduleName":"buildjs/hnav.framework.js","startTimestamp":1442255975619,"fileSize":2443141,"loadTime":1737,"evalTime":2126},{"moduleName":"buildjs/hnav.index.js","startTimestamp":1442255975624,"fileSize":487047,"loadTime":950,"evalTime":456}],"packageType":"PROD"},"version":"0.5.10.12","clientIp":"192.168.1.10"}

Please help me with the regex for it

1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try this. It will extract the modules and times into multi-value fields. It then combines the fields and breaks them into separate events.

...  | rex max_match=0 "\{\"moduleName\":\"(?P<module>[^\"]*).*?\"loadTime\":(?P<loadTime>\d+),\"evalTime\":(?P<evalTime>\d+)}" | eval fields = mvzip(mvzip(module,loadTime),evalTime) | mvexpand fields |...
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Try this. It will extract the modules and times into multi-value fields. It then combines the fields and breaks them into separate events.

...  | rex max_match=0 "\{\"moduleName\":\"(?P<module>[^\"]*).*?\"loadTime\":(?P<loadTime>\d+),\"evalTime\":(?P<evalTime>\d+)}" | eval fields = mvzip(mvzip(module,loadTime),evalTime) | mvexpand fields |...
---
If this reply helps you, Karma would be appreciated.

skoelpin
SplunkTrust
SplunkTrust

Here's some untested regex which will work. Make sure to check the non-matches and see if there's anything left out

(?P<LoadTime>(?=\"loadTime\"\:)\d{2,6})
(?P<evalTime>(?=\"evalTime\"\:)\d{2,6})
0 Karma

harish0557
Explorer

but i want it for specific modules like - require.min.js , framework.js, index.js

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What's New in Splunk Enterprise Security (ES) 8.6

Purpose-Built AI Agents for the Agentic SOC  Splunk Enterprise Security 8.6 expands AI in Security with ...

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...