Security

extract username for element in path

kritho
Explorer

Hi,
Im new to regexes, and I'm trying to get the username field configuration to my extract-fields

source:
/u01/somedir/somedir/user1/anotherfile
/u01/somedir/somedir/user3/anotherfile2
/u01/somedir/somedir/user4/anotherfile3

I want to get the "user1|2|3" part to a username field.

Any tips?
brgds/K

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

To do that inline in the search, you can use rex in the example below, look at the fourth element of the path (i.e. source);

your search | rex field=source "/([^/]+/){3}(?<username>[^/]+)"

/K

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...