Splunk Search

What is the rex command to extract my field?

nivethainspire_
Explorer

what is the rex command to extract the below highlighted field.
2015-12-22 22:40:13 ID="87602", Data_Name="sap01 "DDC - PVD - UDB SPP42 (LDTC1)"", Data_Type="DB2"

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try this search query

... | rex field=Data_Name "\s(?<field>[^\s]+)\s(?=\()" | ...
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...