You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk新手求助:提取字段最后斜杠后、点后的目标内容

Hey there! Let's get those fields trimmed down to exactly what you need. As someone who's been there with Splunk regex headaches as a beginner, here are a couple of straightforward ways to make this work:

Option 1: Extract the right values in one go (cleanest approach)

Instead of pulling the full paths first and then trimming them, we can write a precise regex to grab only filename1 and testname1 directly from your raw log. Here's the full command:

| rex field=_raw "\((?<FILE_NAME>[^/,]+)(?=,.*\))\)\s+(?<TEST_NAME>[^.]+)$"
| table FILE_NAME, TEST_NAME

Quick breakdown of how this regex works:

  • \(: Matches the opening parenthesis before your file path
  • (?<FILE_NAME>[^/,]+)(?=,.*\)): Captures all characters that aren't / or , (this is your filename1)—the positive lookahead (?=,.*\)) ensures we stop right before the comma and line number
  • \)\s+: Matches the closing parenthesis and any whitespace after it
  • (?<TEST_NAME>[^.]+)$: Captures all characters that aren't . from the end of the string (this is your testname1)

Option 2: Trim your existing extracted fields

If you want to keep your original rex command that pulls the full paths, you can add two more rex lines to clean up the fields after extraction:

| rex field=_raw (?<UNW>\S+)\s+(?<UNWA>\S+)\s+(?<FILE_NAME>\S+)\s+(?<TEST_NAME>\S+)
| rex field=FILE_NAME "(?<FILE_NAME>[^/,]+)(?=,)"  // Keeps only text after last / and before ,
| rex field=TEST_NAME "(?<TEST_NAME>[^.]+)$"        // Keeps only text after last .
| table FILE_NAME, TEST_NAME

This works by overwriting the original FILE_NAME and TEST_NAME fields with the trimmed values we want.

Either approach will give you a table with exactly the filename and test name you need. Let me know if you want to dive deeper into any part of the regex!

内容的提问来源于stack exchange,提问作者Priya Ramakrishnan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 22:27:36