Splunk Search

Create new Field Extraction regex expression via REST API Java SDK

misteryuku
Communicator

I have created a new field extraction on props.conf via Splunk REST API

I have a raw message that looks like this.
field1=Happy,field2=Sad,field3=Angry, messenger : my message, keyer : jun

i put in the regex expression to extract jun from the raw message into a search time field called hhj.

the regex that i generated from the IFX was this : (?!)keyer : (P.+)

Using the Java SDK to create the new field extraction via Splunk REST API
RequestMessage reqMsg = new RequestMessage();
reqMsg.setMethod("post");
reqMsg.setContent("name=hhj&stanza=source::sample&type=EXTRACT&\value=(?i) messenger : (?P.+)\"");
authService.send("/servicesNS/admin/search/data/props/extractions",reqMsg);

When i viewed the props.conf file, it gave me

[source::sample]
EXTRACT-hhj = (?i) keyer : (?P.)

The plus + sign inside the regex that i set through the rest endpoint was missing.
How do i make sure that the plus sign appears whenever i create the search time field extraction via the REST endpoint using Java for the above regex that i set.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You need to URL-encode any form data that you post. You can use the java method java.net.URLEncoder.encode() for this.

Incidentally, you're not really using the Splunk Java SDK here. You are actually just working directly with the REST API from Java here. That's fine, as the REST API is fully supported. But the SDK in general should not require you to be getting into the details of making HTTP/REST calls work.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...