<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic regular expression in Security</title>
    <link>https://community.splunk.com/t5/Security/regular-expression/m-p/699926#M18128</link>
    <description>&lt;P&gt;Hi I want to extract highlighted part&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Sep&lt;/SPAN&gt; &lt;SPAN class=""&gt;24&lt;/SPAN&gt; &lt;SPAN class=""&gt;10:43:25&lt;/SPAN&gt; &lt;FONT color="#FFFF00"&gt;&lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt;&lt;/FONT&gt; [&lt;SPAN class=""&gt;S=217&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;RAISE-ALARM&lt;/SPAN&gt;:acProxyConnectionLost:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;KOREASBC1&lt;/SPAN&gt;] &lt;SPAN class=""&gt;Proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;Set&lt;/SPAN&gt; &lt;SPAN class=""&gt;Alarm&lt;/SPAN&gt; &lt;SPAN class=""&gt;Proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;Set&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; (&lt;SPAN class=""&gt;PS_ITSP&lt;/SPAN&gt;)&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;lost.&lt;/SPAN&gt; &lt;SPAN class=""&gt;looking&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;another&lt;/SPAN&gt; &lt;SPAN class=""&gt;proxy&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Severity:major&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Source:Board#1/ProxyConnection#1&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Unique&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:242&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info1:&lt;/SPAN&gt;; [&lt;SPAN class=""&gt;Time:24-09@17:43:25.248&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;63380759]&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 24 Sep 2024 11:27:00 GMT</pubDate>
    <dc:creator>Siddharthnegi</dc:creator>
    <dc:date>2024-09-24T11:27:00Z</dc:date>
    <item>
      <title>regular expression</title>
      <link>https://community.splunk.com/t5/Security/regular-expression/m-p/699926#M18128</link>
      <description>&lt;P&gt;Hi I want to extract highlighted part&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Sep&lt;/SPAN&gt; &lt;SPAN class=""&gt;24&lt;/SPAN&gt; &lt;SPAN class=""&gt;10:43:25&lt;/SPAN&gt; &lt;FONT color="#FFFF00"&gt;&lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt;&lt;/FONT&gt; [&lt;SPAN class=""&gt;S=217&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;RAISE-ALARM&lt;/SPAN&gt;:acProxyConnectionLost:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;KOREASBC1&lt;/SPAN&gt;] &lt;SPAN class=""&gt;Proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;Set&lt;/SPAN&gt; &lt;SPAN class=""&gt;Alarm&lt;/SPAN&gt; &lt;SPAN class=""&gt;Proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;Set&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; (&lt;SPAN class=""&gt;PS_ITSP&lt;/SPAN&gt;)&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;lost.&lt;/SPAN&gt; &lt;SPAN class=""&gt;looking&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;another&lt;/SPAN&gt; &lt;SPAN class=""&gt;proxy&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Severity:major&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Source:Board#1/ProxyConnection#1&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Unique&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:242&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info1:&lt;/SPAN&gt;; [&lt;SPAN class=""&gt;Time:24-09@17:43:25.248&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;63380759]&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 24 Sep 2024 11:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/regular-expression/m-p/699926#M18128</guid>
      <dc:creator>Siddharthnegi</dc:creator>
      <dc:date>2024-09-24T11:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: regular expression</title>
      <link>https://community.splunk.com/t5/Security/regular-expression/m-p/699928#M18129</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257462"&gt;@Siddharthnegi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "^\w+\s\d+\s\d+:\d+:\d+\s(?&amp;lt;ip&amp;gt;\d+\.\d+\.\d+\.\d+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/Ha7ifi/1" target="_blank"&gt;https://regex101.com/r/Ha7ifi/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 12:07:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/regular-expression/m-p/699928#M18129</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-24T12:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: regular expression</title>
      <link>https://community.splunk.com/t5/Security/regular-expression/m-p/699930#M18130</link>
      <description>&lt;P class="lia-align-left"&gt;You can use below rex. Which will fetch the highlighted context&lt;BR /&gt;| rex "\w+\s+\d+\s+\d{2}:\d{2}:\d{2}\s+(?&amp;lt;result&amp;gt;[^\s]+)"&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 12:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/regular-expression/m-p/699930#M18130</guid>
      <dc:creator>Thulasinathan_M</dc:creator>
      <dc:date>2024-09-24T12:09:57Z</dc:date>
    </item>
  </channel>
</rss>

