Splunk Search

RegEx Extract value after string

arrowecssupport
Communicator

I'm trying to build an extraction to find the uptime from this data (example below)

.1.3.6.1.4.1.789 Enterprise Specific Trap (87) Uptime: 0:27:51.35
.1.3.6.1.3.94 Enterprise Specific Trap (4) Uptime: 195 days, 7:01:04.00

Can anyone help with the RegEx?

Tags (1)
0 Karma
1 Solution

niketn
Legend

@arrowecssupport, based on the sample data you can use the following rex command:

| rex "Uptime:\s(?<uptime>.*)"

Please find below the tun anywhere search, which extracts the uptime value and also uses convert command function dur2sec() to convert D+HH:MM:SS to seconds.

| makeresults
| eval data=".1.3.6.1.4.1.789 Enterprise Specific Trap (87) Uptime: 0:27:51.35;.1.3.6.1.3.94 Enterprise Specific Trap (4) Uptime: 195 days, 7:01:04.00"
| makemv data delim=";"
| mvexpand data
| rename data as _raw
| rex "Uptime:\s(?<uptime>.*)"
| eval uptime_seconds=replace(replace(uptime,"\sdays,\s","+"),"\..+","")
| convert dur2sec(uptime_seconds)
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@arrowecssupport, based on the sample data you can use the following rex command:

| rex "Uptime:\s(?<uptime>.*)"

Please find below the tun anywhere search, which extracts the uptime value and also uses convert command function dur2sec() to convert D+HH:MM:SS to seconds.

| makeresults
| eval data=".1.3.6.1.4.1.789 Enterprise Specific Trap (87) Uptime: 0:27:51.35;.1.3.6.1.3.94 Enterprise Specific Trap (4) Uptime: 195 days, 7:01:04.00"
| makemv data delim=";"
| mvexpand data
| rename data as _raw
| rex "Uptime:\s(?<uptime>.*)"
| eval uptime_seconds=replace(replace(uptime,"\sdays,\s","+"),"\..+","")
| convert dur2sec(uptime_seconds)
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...