Splunk Search

rex field message

indeed_2000
Motivator

Hi
what is the rex for this
field1=this is message

here is the log:
00:09:59.990 app module: AB[0000]: Data[{"code":"OK","messageEn":"this is message","messageCa":null,"id":"0"}

Thanks,

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex "messageEn\":\"(?<field1>[^\"]+)"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "messageEn\":\"(?<field1>[^\"]+)"
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...