Splunk Search

Extracting fields using regex

kailun92
Communicator

When i try to extract a field using this (?i)humidity : (?P.+) expression. The result below is given. Is there anyway to extract just 0.82 which is the humidity I needed ? Need help on this, thanks in advance 😃

0.82
icon : cloudy
ozone : 263.15
precipIntensity : 0.001
precipProbability : 0.05
precipType : rain
pressure : 1005.57
summary : Dry and Overcast
temperature : 80.94

1 Solution

chris
Motivator

How about:

(?i)humidity : (?P<fieldname>[\d\.]+)

View solution in original post

chris
Motivator

How about:

(?i)humidity : (?P<fieldname>[\d\.]+)

kailun92
Communicator

Check you with you, do you know how to extract summary : Dry and Overcast ? Same situation. If cannot then how about icon ? how to extract the words out ? I am extraction the part below it also.

0 Karma

kailun92
Communicator

Thank you SO MUCH, i love you i have been solving for so long

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...