Hi,
I believe you want to extract the value of the status field (i.e status = 2 then you want to extract 2 as the value of the status field)
If you want to go for regex expression. your expression would look like ''Status'\W+(?\d+)'. Now that you have the regex expression. you can go to your splunk UI and there in the fields sidebar, scroll down you will see a '+' sign with "extract new fields">> click on it.
You will see the option as "I prefer writing my own regular expression" click on that. And put the above specified regex expression there.
preview your extracted field
click save
And then you would get an extracted field as "status" in the fields side bar.
To know more about the regex expressions you can practice it here ----> "https://regex101.com/"
... View more