Hi,
I am newbie to splunk,We are looking to extract a field from below event format.
"PDR Message Listener Completed Processing Message"
From above , we need to extract a field after "PDR Message Listener" as field called status as "Completed", Can someone help extraction using Rex command.
we tried using field extrcation from events ,but it is giving us some false results.
If you always have "PDR Message Listener" before the status value you want to capture, try this
your base search | rex "PDR Message Listener Completed (?<status>\s+)"
If the string before status value is not constant but always 3 words, then try this
your base search | rex "^(\w+\s){3}(?<status>\s+)"
If you always have "PDR Message Listener" before the status value you want to capture, try this
your base search | rex "PDR Message Listener Completed (?<status>\s+)"
If the string before status value is not constant but always 3 words, then try this
your base search | rex "^(\w+\s){3}(?<status>\s+)"
I think the capture group should be (?<status>\w+)
and not use \s+, right?
edit: formatting
or if you want to use \s
then it should be "^(\w+\s){3}(?<status>[^\s]+)"