Hi, In the following log, I wanted to extract Url, Method, ResponseTimeMs, StatusCode as a table: log: a_level="INFO", a_time="null", a_sub="xxx", a_uid="xx", a_tid="xx", a_rid="guid", a_thread="175" a_type="type", a_met="Move", a_msg="Method=GET,Uri=http://monolith-xxx.abc.com/v2/clients?skip=0top=100,MediaType=null,RemoteIP=::ffff:10.10.10.10,XRemoteIP=null,ContentType=application/json,ContentLength=9702,ResponseTimeMs=54,StatusCode=200,ReasonPhrase=null,Referrer=null For URL, I wanted the full extract "http://monolith-xxx.abc-xyz/v2/clients?skip=0top=100" My current splunk query is as below: index=aws_abc env=prd-01 uri Method StatusCode ResponseTimeMs | eval DataSet=log | rex field=DataSet "ResponseTimeMs=(?<ResponseTimeMs>\d+),StatusCode=(?<StatusCode>\d+)" | rex field=DataSet "Url=(?<uri>[^,]+),Method=(?<Method>\w+)" | table Url,Method,ResponseTimeMs, StatusCode I get value in the table for ResponseTimeMs, StatusCode but not for URL and Method. Please help. Thanks
... View more