Splunk Search

how to read comment line

pragycho
Loves-to-Learn

Hi ,

I have data where  i  want to read comment line and store value in field.

for example  , I have log where first  4 line field is in commented for Version, Date, System, Software

#Version: 1.0
#Date: 2020-04-18 11:10:15
#System: 10.244.32.81 - SCWSA-7HBA-0001.nbnco.local
#Software: ABC for Web 11.8.0-414

My query  : i have 4 field in datamodel for ver , date, system, software .now i want to store commented data in this field. so how to write the regex expression for this so-that i can see value in datamodel for this commented line

Labels (3)
0 Karma

pragycho
Loves-to-Learn

thanks for replying

0 Karma

alonsocaio
Contributor

Hi @pragycho , this could be used as a generic regex for extracting these fields:

\#\w+\:\s(.+)$

If you need a regex for each field, you can try something like this:

\#Version\:\s(?<version>.+)$
\#Date\:\s(?<date>.+)$
\#System\:\s(?<system>.+)$
\#Software\:\s(?<software>.+)$

 

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Developer Program!

Hey Splunk community! We are excited to announce that Splunk is launching the Splunk Developer Program in ...

Splunkbase Year in Review 2024

Reflecting on 2024, it’s clear that innovation and collaboration have defined the journey for Splunk ...

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...