Splunk Search

To extract string value using regex

parthiban
Path Finder

Hi Team,

I want to extract the below field value, here the challenge is the error code 403 sometimes it will change.

"processing_stage": "Getting a response of 403 from CRM Lead"

 

Kindly help me to extract the message using regex or any option available.

Labels (3)
0 Karma

parthiban
Path Finder

Hi @gcusello 

It is not working as expected, I need to extract full string

parthiban_0-1709554414427.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @parthiban,

you hughlighted only the 403 response code, if you want the full string, you could use:

| rex "\"processing_stage\": \"(?<response>[^\"]+)"

that you can test at https://regex101.com/r/mz4c1L/2 

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @parthiban,

if the message string is fixed, you could try:

<your_search> 
| rex "\"Getting a response of (?<response>\d+)"
| table ...

you can test this regex at https://regex101.com/r/mz4c1L/1

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...