Splunk Search

What is the rex command to extract the last value from a source field?

Path Finder

Hi .. I need to extract back123 from the source field. pls provide the entire rex command needed to fetch back123 to a new field.

source = /opensource/final/back123

0 Karma

Splunk Employee
Splunk Employee

Hi @simona2121 - Looks like you have several answers to try out 🙂 If one of them has worked, please click "Accept" below the best answer to resolve this post. Thank you!

0 Karma

Super Champion

Joining the answer party...

Try this

source = "*opensource*" | dedup source | rex field=source ".*\/(?<new>.*)" | table source, new
0 Karma


This should do:

... | rex field=source ".*\/(?<new>\S+)"


0 Karma


Let's make it an even 4

... | rex field=source "\/(?<folder>[^\/]*)$"
0 Karma

Esteemed Legend

Like this:

... | rex field=source ".*?(?<fn>[^\/]*)$"
0 Karma


Try this:

 yoursearch | rex field=source ".*\/(?[^ ]+)" | table myfield


0 Karma

Super Champion

if that source is part of your event, then field=_raw is good.

yoursearch | rex field=_raw "final\/(?<rexField>.*)" | table rexField

if that source is splunk extracted source field, then field=source is good.

yoursearch | rex field=source "final\/(?<rexField>.*)" | table rexField
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!