Splunk Search

Get a value from Search

abhi144
New Member

I have a search which is coming with this field-

timezone=America/Montreal(EDT)offset-14400(Daylight).

so how can i get only EDT? Any suggestion will be appreciated.

Tags (2)
0 Karma

MuS
Legend

Hi,

something like this should work:

... | rex field="timezone" "\((?<myTZ>[A-Z]+)\)" | ...

this will create a new field called myTZ

cheers, MuS

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...