Splunk Search

Splunk multiple field extraction

ppatkar
Path Finder

 

 I have the below Splunk Event & need to extract multiple fields from the same :

 

[TIMESTAMP=2021-02-19 12:16:30.684 UTC] [RUN_ID=] [TRACE_ID=] [STEP=End Processing] [LINE_NO=701] [LOG_LEVEL=TRACE] [MESSAGE=[ppv] [insert] Query completed , total 11 ms: [10 values] INSERT INTO errors (job,run,timestamp,count,alert,error,code,message,completets,active) VALUES (?,?,?,?,?,?,?,?,?,?); [job:'endcustomer--prod', run:'4569876', timestamp:1613736990530, count:200, alert:'failed after launch', error:'', code:'E302: Batch failed', message:'', completets:'', active:false]]

 

Expected Table Output :

jobruncode
endcustomer--prod4569876E302: Batch failed

 

I was able to pick some field like :

run\:\'(?<run>\w+)'

https://regex101.com/r/q7NqQb/1

However, unable to extract all the three fields above. Any help is appreciated.

Labels (2)
0 Karma
1 Solution

manjunathmeti
Champion

hi @ppatkar,

Use rex command twice:

| rex "job:'(?<job>[^']+)',\srun:'(?<run>[^']+)"
| rex "code:'(?<code>[^']+)'"
| table job, run, code

 

If this reply helps you, an upvote/like would be appreciated.

View solution in original post

jotne
Builder

All in on rex

 

Your search
| rex "job:'(?<job>[^']+)'. run:'(?<run>[^']+)'.*? code:'(?<code>[^']+)'"
| table job run code

 

manjunathmeti
Champion

hi @ppatkar,

Use rex command twice:

| rex "job:'(?<job>[^']+)',\srun:'(?<run>[^']+)"
| rex "code:'(?<code>[^']+)'"
| table job, run, code

 

If this reply helps you, an upvote/like would be appreciated.

ppatkar
Path Finder

Hi @manjunathmeti 

I have one followup to the earlier , in certain events I see truncated output like below :

 

[TIMESTAMP=2021-02-19 12:16:30.684 UTC] [RUN_ID=] [TRACE_ID=] [STEP=End Processing] [LINE_NO=701] [LOG_LEVEL=TRACE] [MESSAGE=[ppv] [insert] Query completed , total 11 ms: [10 values] INSERT INTO errors (job,run,timestamp,count,alert,error,code,message,completets,active) VALUES (?,?,?,?,?,?,?,?,?,?); [job:'endcustomer--pr..[truncated output], run:4569876, timestamp:1613736990530, count:200, alert:'failed after launch', error:'', code:'E302: Batch failed', message:'', completets:'', active:false]]

 

This is causing my job to get derived as null . Can you please advise ?

 

0 Karma

manjunathmeti
Champion

Try this:

| rex "job:'?(?<job>[^']+)'?,\srun:'?(?<run>\d+)'?"
| rex "code:'(?<code>[^']+)'"
| table job, run, code

 

 If this reply helps you, an upvote/like would be appreciated.

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...