<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex match in a Splunk lookup in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758295#M4170</link>
    <description>&lt;P&gt;Lookups don't use regexes for matching (unless you're talking about an "external lookup" - there you can implement everything you like).&lt;/P&gt;&lt;P&gt;But.&lt;/P&gt;&lt;P&gt;If we're talking about csv-based lookups the entries are inspected in the order they're written in the file. So if you set maximum matches to 1 and give a negative match early in the file you can prevent Splunk from matching positively later in the file. It's kinda ACL-like behaviour.&lt;/P&gt;&lt;P&gt;But yes, that's ugly.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2026 20:59:14 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2026-02-12T20:59:14Z</dc:date>
    <item>
      <title>Regex match in a Splunk lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758269#M4168</link>
      <description>&lt;P&gt;Hello great Splunk community&lt;/P&gt;&lt;P&gt;I have a requirement to match fqdn's based on regex. So:&lt;BR /&gt;&lt;BR /&gt;I have a wildcard lookup that has FQDN's and say, another field "&lt;STRONG&gt;match"&lt;/STRONG&gt; which is true in the case of a successful match.&lt;/P&gt;&lt;P&gt;For example in the lookup I have an entry&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;*.website.com&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;I want to match anything that is abc.website.com or xyz.website.com&lt;BR /&gt;&lt;BR /&gt;However,&lt;/P&gt;&lt;P&gt;I don't want to match stuff that is in the form of def.abc.website.com or uvw.xyz.website.com.&lt;BR /&gt;&lt;BR /&gt;Wildcard tends not to care about anything before the as long as the string after * matches. Any ideas how to do that?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 06:09:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758269#M4168</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2026-02-12T06:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Regex match in a Splunk lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758295#M4170</link>
      <description>&lt;P&gt;Lookups don't use regexes for matching (unless you're talking about an "external lookup" - there you can implement everything you like).&lt;/P&gt;&lt;P&gt;But.&lt;/P&gt;&lt;P&gt;If we're talking about csv-based lookups the entries are inspected in the order they're written in the file. So if you set maximum matches to 1 and give a negative match early in the file you can prevent Splunk from matching positively later in the file. It's kinda ACL-like behaviour.&lt;/P&gt;&lt;P&gt;But yes, that's ugly.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 20:59:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758295#M4170</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-02-12T20:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Regex match in a Splunk lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758301#M4171</link>
      <description>&lt;P&gt;As PickleRick says, you can't do regex in lookup directly, but I've used his technique through a programatically managed/ordered lookup, where I have ordered the results based on wildcards, so that first hit is counted only.&lt;/P&gt;&lt;P&gt;If your rule is sufficiently tight that the wildcards is matching domain segments rather parts of the segment, then you could do post matching on the part counts&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval fqdn1="abc.website.com"
| eval result="*.website.com" ``` lookup returns ```
| eval fqdn1_count=mvcount(split(fqdn1, ".")), result_count=mvcount(split(result, "."))
| eval match1=if(fqdn1_count=result_count, "HIT", "MISS")

| eval fqdn2="def.abc.website.com"
| eval result="*.website.com" ``` lookup returns ```
| eval fqdn2_count=mvcount(split(fqdn2, ".")), result_count=mvcount(split(result, "."))
| eval match2=if(fqdn2_count=result_count, "HIT", "MISS")&lt;/LI-CODE&gt;&lt;P&gt;You'd have to do a bit more work to manage multiple results, e.g. if you have *.*.website.com in your lookup, a lookup for def.abc.website.com would get 2 hits.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 03:19:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758301#M4171</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2026-02-13T03:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Regex match in a Splunk lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758360#M4174</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Here's an alternative using a single eval, which you can implement as a macro:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;wildcard_domains.csv&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;domain
*.example.com&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[wildcard_domains]
batch_index_query = 0
case_sensitive_match = 0
filename = wildcard_domains.csv
match_type = WILDCARD(domain)
max_matches = 1
min_matches = 0&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;SPL&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;| makeresults format=csv data="
domain
foo.example.com
bar.example.com
bar.baz.example.com
"
| eval wildcard_domain_match=if(match(domain, replace(replace(spath(lookup("wildcard_domains", json_object("domain", domain), json_array("domain")), "domain"), "\\.", "\\."), "^\\*", "^[^.]+")), 1, 0)&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;Result&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;domain	               wildcard_domain_match
foo.example.com	                           1
bar.example.com	                           1
bar.baz.example.com                        0&lt;/LI-CODE&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;noted, the order of the entries in wildcard_domains.csv is important. The first match "wins."&lt;/P&gt;&lt;P&gt;If I were doing this for myself, I would write an external lookup and use a standard or reference library for wildcard label matching rules relative to the use case: DNS, TLS, X.509, etc. Those examples follow the same general rules for leftmost label matching, but you may have other requirements.&lt;/P&gt;&lt;P&gt;(Edited to remove mvmap. I started writing a response with max_matches &amp;gt;= 1. I can provide an example if you need one.)&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2026 17:00:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Regex-match-in-a-Splunk-lookup/m-p/758360#M4174</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2026-02-14T17:00:02Z</dc:date>
    </item>
  </channel>
</rss>

