Splunk Search

rex to extract a field

Mohsin123
Path Finder

How do I extract connection attempt failed from the below log

2017-12-20T07:51:05.847Z I REPL [ReplicationExecutor] Error in heartbeat request to 10.78.33.13:8191; Location18915 Failed attempt to connect to 10.78.33.13:8191; couldn't connect to server 10.78.33.13:8191 (10.78.33.13), connection attempt failed

Tags (1)
0 Karma

nickhills
Ultra Champion

try this:
(?<err_message>Error.+;).+,(?<err_reason>.+)

It will extract two fields - err_message and err_reason

If my comment helps, please give it a thumbs up!
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi shraddhamuduli,
which information do you want to extract?
if you want to extract the message "connection attempt failed", it's easy

| rex ".*\),(?<my_field>.*)$"

if you want to extract other fields (e.g. server and port failed), it's

| rex ".*server\s(?<ip>\d+\.\d+\.\d+\.\d+):(?<port>\d+)"

Bye.
Giuseppe

harsmarvania57
Ultra Champion

Hi,

Can you please try <yourBasesearch> | rex ".*,\s(?<status>.*)", this will extract connection attempt failed in new field called status

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...