Splunk Search

rex to extract a field

Mohsin123
Path Finder

How do I extract connection attempt failed from the below log

2017-12-20T07:51:05.847Z I REPL [ReplicationExecutor] Error in heartbeat request to 10.78.33.13:8191; Location18915 Failed attempt to connect to 10.78.33.13:8191; couldn't connect to server 10.78.33.13:8191 (10.78.33.13), connection attempt failed

Tags (1)
0 Karma

nickhills
Ultra Champion

try this:
(?<err_message>Error.+;).+,(?<err_reason>.+)

It will extract two fields - err_message and err_reason

If my comment helps, please give it a thumbs up!
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi shraddhamuduli,
which information do you want to extract?
if you want to extract the message "connection attempt failed", it's easy

| rex ".*\),(?<my_field>.*)$"

if you want to extract other fields (e.g. server and port failed), it's

| rex ".*server\s(?<ip>\d+\.\d+\.\d+\.\d+):(?<port>\d+)"

Bye.
Giuseppe

harsmarvania57
Ultra Champion

Hi,

Can you please try <yourBasesearch> | rex ".*,\s(?<status>.*)", this will extract connection attempt failed in new field called status

Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...