Splunk Search

field extraction

sandeepmakkena
Contributor

I have a filed that has value something like this:

ww.abcd.hongkong
ww.abcd.cn
ww.abcd.asiaenglish.ph
ww.abc.us

I want to extract last part of this as country filed. Can someone help with regular expression please.

Thank you.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi sandeepmakkena,
try this regex:

! rex field=my_field "(?<contry>\w+)$"

You can test it at https://regex101.com/r/gNwfuc/1

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi sandeepmakkena,
try this regex:

! rex field=my_field "(?<contry>\w+)$"

You can test it at https://regex101.com/r/gNwfuc/1

Bye.
Giuseppe

View solution in original post

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!