Splunk Search

Use named backreference in the subsequent rex command

Murali2888
Communicator

Hi All,

Can you let me know how we can use a named backreference in the subsequent rex command? That is pass the value of the named backreference to the next rex command.

I am trying something like below which is not providing the desired result.

rex "<tag1>(?P<NamedField1>[^<]+" | rex "<tag2>?(P=NamedField1)</tag2><tag3>(?P<NamedField2>)" | table NamedField2

If someone could point out some documentation around this that would be very helpful.

0 Karma

maciep
Champion

Not exactly what you're asking, but you can use \n to represent a previously captured group in the same rex command. So in your case, something like

rex "<tag1>(?P<NamedField1>[^<]+").+<tag2>\1</tag2><tag3>(?P<NamedField2>)" 

Although I'm pretty sure i found a way to substitute field names in the rex too, but don't remember and could be mistaken.

0 Karma

Murali2888
Communicator

Thanks maciep.

I had this option, but unfortunately the xml structure is quite redundant and complex which would not allow using a single rex command. Nevertheless, I had found some workaround with eval command.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...