Splunk新手求助:提取字段最后斜杠后、点后的目标内容
Hey there! Let's get those fields trimmed down to exactly what you need. As someone who's been there with Splunk regex headaches as a beginner, here are a couple of straightforward ways to make this work:
Option 1: Extract the right values in one go (cleanest approach)
Instead of pulling the full paths first and then trimming them, we can write a precise regex to grab only filename1 and testname1 directly from your raw log. Here's the full command:
| rex field=_raw "\((?<FILE_NAME>[^/,]+)(?=,.*\))\)\s+(?<TEST_NAME>[^.]+)$" | table FILE_NAME, TEST_NAME
Quick breakdown of how this regex works:
\(: Matches the opening parenthesis before your file path(?<FILE_NAME>[^/,]+)(?=,.*\)): Captures all characters that aren't/or,(this is yourfilename1)—the positive lookahead(?=,.*\))ensures we stop right before the comma and line number\)\s+: Matches the closing parenthesis and any whitespace after it(?<TEST_NAME>[^.]+)$: Captures all characters that aren't.from the end of the string (this is yourtestname1)
Option 2: Trim your existing extracted fields
If you want to keep your original rex command that pulls the full paths, you can add two more rex lines to clean up the fields after extraction:
| rex field=_raw (?<UNW>\S+)\s+(?<UNWA>\S+)\s+(?<FILE_NAME>\S+)\s+(?<TEST_NAME>\S+) | rex field=FILE_NAME "(?<FILE_NAME>[^/,]+)(?=,)" // Keeps only text after last / and before , | rex field=TEST_NAME "(?<TEST_NAME>[^.]+)$" // Keeps only text after last . | table FILE_NAME, TEST_NAME
This works by overwriting the original FILE_NAME and TEST_NAME fields with the trimmed values we want.
Either approach will give you a table with exactly the filename and test name you need. Let me know if you want to dive deeper into any part of the regex!
内容的提问来源于stack exchange,提问作者Priya Ramakrishnan

