Splunk Search

How to extract a field from raw using rex?

kavyamohan
Explorer
SVSCPLEX,S0W1,S0W1.DAL-EBIS.IHOST.COM,SYSLOG,zOS-SYSLOG-Console,SYSLOG,-0400,NE,001C,19283 01.21.46.880
 -0500,S0W1    ,JOB03487,        ,40000000000000000000000000000000,00000090,TESCREAT,00," IEF450I TESCREAT STEP010 - ABEND=S222 U0000 REASON=00000000"\n

How to extract JOB03487 from this _raw? can anyone help?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi kavyamohan,
try this

| rex "([^7]*,){5}(?<job>[^,]*),"

you can test it at https://regex101.com/r/eW7oCi/1

Ciao.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi kavyamohan,
try this

| rex "([^7]*,){5}(?<job>[^,]*),"

you can test it at https://regex101.com/r/eW7oCi/1

Ciao.
Giuseppe

kavyamohan
Explorer

Thank you it worked

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...