Splunk Search

Rex formatting trouble

MikeB
Path Finder

Hello again Spelunkers! 

So I have data that looks like this:

assessment=normal [1.0]
assessment=normal [1.1]
assessment=suspect [0.75]
assessment=suspect [0.88]
assessment=bad [0.467]


I want a table column named rating that takes the "normal," "suspect," "bad" without the [###] after it. So I wrote the below thinking I can name the column rating and then capture any alpha characters and terminate at the white space between the word value and the [###] value. What would be the correct way of writing this? Thank you in advance!

 

| rex field=raw_ "assessment=(?<rating>/\w/\s)"

 



Labels (1)
Tags (3)
0 Karma
1 Solution

danielcj
Path Finder

Hi,

 

Please, try the following:

| rex field=_raw "assessment=(?<rating>\S+)"



View solution in original post

0 Karma

danielcj
Path Finder

Hi,

 

Please, try the following:

| rex field=_raw "assessment=(?<rating>\S+)"



View solution in original post

0 Karma

MikeB
Path Finder

Thank you! This worked perfectly. 

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!