Splunk Search

rex for three fields

indeed_2000
Builder

hi 

what is rex for these three fields?

here is the log:
2021-10-14 12:51:20,412 INFO [APP] log in : A12345@#4321@california
2021-10-14 12:51:20,412 INFO [APP] log in : D12345@torrento
2021-10-14 12:51:20,412 INFO [APP] log in : B12345@#1234@newyork

field1=A12345
D12345
B12345

field2=4321
1234

field3=california
torrento
newyork

 

thanks

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex ":\s(?<field1>[^@]+)@(#(?<field2>[^@]+)@|)(?<field3>.+)"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| rex ":\s(?<field1>[^@]+)@(#(?<field2>[^@]+)@|)(?<field3>.+)"

View solution in original post

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!