Splunk Search
Highlighted

Splunk rex field extraction issue

New Member

Hi Guys,

I have to extract one field from the below log and i tried this regex in https://rubular.com/ "(?<=^4Nett\s\W\W)(\W.*)$" This regex exactly working what i am looking for.

Status report: "<App name> :: <Status>"
ABC_Service :: Started in 2 sec

but when i try this in splunk it is not giving me the extracted field.

<base query>|rex (?<Application_status><=^4Nett\s\W\W)(\W.*)$

My expected result
Started in 2 sec

Please give me a hint what i am missing here

Tags (2)
0 Karma
Highlighted

Re: Splunk rex field extraction issue

SplunkTrust
SplunkTrust

@dineshCool,

If you have the :: delimiter always in the events try

rex "::\s+(?<Application_Status>.*)"

View solution in original post

0 Karma