Splunk Search

extract the value for the field

hashsplunk
Loves-to-Learn Lots

incoming/d0000c00002/data_reuse/d000/d0000c00002/ar/shared/sdtm/prod/data/idap_20191011/dm.sas7bdat

 

what I need is to extract only d0000c00002 before data _reuse

Labels (1)
0 Karma

hashsplunk
Loves-to-Learn Lots

Sometimes the data looks like below without the prefix incoming 

 

d0000c00004/data_reuse/d000/d0000c00004/ar/shared/adam/prod/data/idap_20191011/adlbh.sas7bdat

i just need to extract before the keyword data_reuse in both cases with and without  incoming 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "(?<field>[^\n\/]+)\/data_reuse"
0 Karma

hashsplunk
Loves-to-Learn Lots

Sorry not working

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults | eval _raw="d0000c00004/data_reuse/d000/d0000c00004/ar/shared/adam/prod/data/idap_20191011/adlbh.sas7bdat"
| rex "(?<field>[^\n\/]+)\/data_reuse"
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "^incoming\/(?<field>[^\/]+)"
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...