Splunk Search
Highlighted

need help in extracting a substring from a string

Explorer

hello splunkers! new to splunk and i am needing to extract a word from a message field.

this is the message

The Cluster Service service entered the running state.

i want to extract "running state" and use it to indicate a status of a server.

thank you!

Labels (1)
Tags (1)
0 Karma
Highlighted

Re: need help in extracting a substring from a string

Motivator

Pipe your existing search to erex, give the field a name and provide an example.

...| erex ServiceState examples="running state"

When your search completes use the job inspector to find the regex that Splunk used to find your match.

https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Erex

View solution in original post

0 Karma
Highlighted

Re: need help in extracting a substring from a string

Explorer

thanks! 🙂

0 Karma
Highlighted

Re: need help in extracting a substring from a string

Explorer

this worked great!!!!!!

0 Karma
Highlighted

Re: need help in extracting a substring from a string

Motivator

Glad it worked for you! erex is a hidden gem 🙂

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.