Splunk Search

how to extract all values separately suing rex command

Puvi
New Member

hi,

i have a string like: AAA TEST BBB 1000 CCC DDD EEE FFF GG 11111
i need to extract all the values separately and display in table..
can you help me in this

Tags (2)
0 Karma

vnravikumar
Champion

Hi

Try this

| makeresults 
| eval test="AAA TEST BBB 1000 CCC DDD EEE FFF GG 11111" 
| rex field=test max_match=0 "(?<output>[^\s]+)" 
| mvexpand output 
| table output
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...