Splunk Search

extract exception from stacktrace field

donB
Loves-to-Learn Lots

Below is a sample log message.  Each message will have string "500 Server Error for HTTP" and i need to extract 3 fields after the occurrence of "500 Server Error for HTTP" string

2020-11-18T00:32:37.632Z LCS userId=null LCE [helper-http-epoll-1] ERROR o.s.b.a.w.r.e.AbstractErrorWebExceptionHandler.error(122) - 500 Server Error for HTTP POST "/sports/v1/boxing"java.net.UnknownHostException: my-rest-service.backend-->	at java.base/java.net.InetAddress$CachedAddresses.get(InetAddress.java:797)-->	Suppressed: reactor.core.publisher.FluxOnAssembly$OnAssemblyException: 

I need to extract 2 fields  -

1) method (e.g. - POST)

2) path (between 1st pair of quotes) - e.g, /sports/v1/boxing

and 2)exception_type (anything between 1st quote closing and before first occurrence of -->)

java.net.UnknownHostException: alert-rest-service.backend-

Splunk query i am trying is below

index="k8s*" messageType=ERROR "*Exception:*-->" 
| rex "500 Server Error for HTTP (?<http_method>\\S+).*\\\\\"(?<resource_url>.*)\\\\\"(?<java_exception>.*?(Exception)).*"

 Query works fine to extract "http_method" and "resource_url"

but "java_exception" is not being extracted properly. Can someone help?

Labels (5)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index="k8s*" messageType=ERROR "*Exception:*-->" 
| rex "500 Server Error for HTTP (?<http_method>\S+).*\\\"(?<resource_url>.*)\\\"(?<java_exception>.*?Exception)"
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...