Splunk Search

rex to export users

indeed_2000
Builder

Hi
what is the spl command to extract users.

Here is the sample:
2021-09-12 21:40:03,938 ERROR [APPNAME] User H83952 invalid: javax.security.auth.login.LoginException:
2021-09-12 21:40:03,938 ERROR [APPNAME] User 83944 invalid: javax.security.auth.login.LoginException:
2021-09-12 21:40:03,938 ERROR [APPNAME] User A_Frok invalid: javax.security.auth.login.LoginException:

expected output:
H83952
83944
A_Frok

Thanks,

0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

e.g. this works

...
| rex "User (?<user>[^\s]+)"

r. Ismo 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

e.g. this works

...
| rex "User (?<user>[^\s]+)"

r. Ismo 

View solution in original post

.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!