Splunk Search

extract the value for the field

hashsplunk
Loves-to-Learn Lots

incoming/d0000c00002/data_reuse/d000/d0000c00002/ar/shared/sdtm/prod/data/idap_20191011/dm.sas7bdat

 

what I need is to extract only d0000c00002 before data _reuse

Labels (1)
0 Karma

hashsplunk
Loves-to-Learn Lots

Sometimes the data looks like below without the prefix incoming 

 

d0000c00004/data_reuse/d000/d0000c00004/ar/shared/adam/prod/data/idap_20191011/adlbh.sas7bdat

i just need to extract before the keyword data_reuse in both cases with and without  incoming 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "(?<field>[^\n\/]+)\/data_reuse"
0 Karma

hashsplunk
Loves-to-Learn Lots

Sorry not working

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults | eval _raw="d0000c00004/data_reuse/d000/d0000c00004/ar/shared/adam/prod/data/idap_20191011/adlbh.sas7bdat"
| rex "(?<field>[^\n\/]+)\/data_reuse"
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "^incoming\/(?<field>[^\/]+)"
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...