<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REGEX in blacklist doesn't work as intended in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REGEX-in-blacklist-doesn-t-work-as-intended/m-p/559284#M66076</link>
    <description>&lt;P&gt;Have you tried using erex to help build your regex? It's a hidden gem, and extremely useful.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Erex" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Erex&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2021 15:38:46 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2021-07-13T15:38:46Z</dc:date>
    <item>
      <title>REGEX in blacklist doesn't work as intended</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REGEX-in-blacklist-doesn-t-work-as-intended/m-p/559254#M66074</link>
      <description>&lt;P&gt;Hello folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I encountered a problem when trying to filter events from WinEventLog and EventCode 4662.&amp;nbsp; When I use the next regex in a tester or in a SPL with a data set unfiltered, it works fine. But using it in a blacklist only allows a fraction of the messages when "Default Property Set" is in the first row after Properties.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;blacklist9 = EventCode="4662" Message="(Tipo\sde\sobjeto:(?!\s*groupPolicyContainer))[\s\S]*(Propiedades:(?![\s\S]*Default Property Set))"&lt;BR /&gt;&lt;BR /&gt;I tried some changes to the regex but I do not find a solution for this. Thanks for your time.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 12:06:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REGEX-in-blacklist-doesn-t-work-as-intended/m-p/559254#M66074</guid>
      <dc:creator>osakachan</dc:creator>
      <dc:date>2021-07-13T12:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: REGEX in blacklist doesn't work as intended</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REGEX-in-blacklist-doesn-t-work-as-intended/m-p/559284#M66076</link>
      <description>&lt;P&gt;Have you tried using erex to help build your regex? It's a hidden gem, and extremely useful.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Erex" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Erex&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 15:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REGEX-in-blacklist-doesn-t-work-as-intended/m-p/559284#M66076</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2021-07-13T15:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: REGEX in blacklist doesn't work as intended</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REGEX-in-blacklist-doesn-t-work-as-intended/m-p/559332#M66085</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/150269"&gt;@osakachan&lt;/a&gt;&amp;nbsp; Can you check are you following allowed regex its little different from PCRE-&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/admin/Inputsconf#Event_Log_allow_list_and_deny_list_formats" target="_blank"&gt;inputs.conf - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 01:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REGEX-in-blacklist-doesn-t-work-as-intended/m-p/559332#M66085</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-14T01:26:40Z</dc:date>
    </item>
  </channel>
</rss>

