<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regex Help in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320470#M4454</link>
    <description>&lt;P&gt;Need help in removing double quotes from extracted field value.&lt;/P&gt;

&lt;P&gt;EVAL-user = nullif(replace(user, "[^:]+:\s*(.*|\w+\,\s\w+\s{\w+})", "\1"),"")&lt;/P&gt;

&lt;P&gt;Sample Log:&lt;BR /&gt;
2017-02-12 14:02:05,Virus found,Source: Scheduled Scan,Risk name: OSX.Trojan.Gen,Occurrences: 1,/Users/71071190/Downloads/archive_manager.dmg,'',Actual action: Deleted,Requested action: Deleted,Secondary action: Deleted,Event time: 2017-02-08 22:38:17,Inserted: 2017-02-12 20:02:05,End: 2017-02-08 22:38:17,Last update time: 2017-02-12 20:02:05,Domain: North America,Group: My Company\North America\Workstations\Macs,User: "ABCD, XYZ {FGH}",Source computer: ,Source IP: ,Disposition: Good,Download site: null,Web domain: null,Downloaded by: null,Prevalence: Reputation was not used in this detection.,Confidence: Reputation was not used in this detection.,URL Tracking Status: Off,,First Seen: Reputation was not used in this detection.,Sensitivity: Low,MDS,Application hash: ,Hash type: SHA1,Company name: ,Application name: ,Application version: ,Application type: -1,File size (bytes): 0,Category set: Security risk,Category type: UNKNOWN&lt;BR /&gt;
2017-02-12 14:02:05,Virus found,Source: Scheduled Scan,Risk name: OSX.Trojan.Gen,Occurrences: 1,/Users/71071190/Downloads/archive_manager.dmg,'',Actual action: Deleted,Requested action: Deleted,Secondary action: Deleted,Event time: 2017-02-08 22:38:17,Inserted: 2017-02-12 20:02:05,End: 2017-02-08 22:38:17,Last update time: 2017-02-12 20:02:05,Domain: North America,Group: My Company\North America\Workstations\Macs,User: 12345678,Source computer: ,Source IP: ,Disposition: Good,Download site: null,Web domain: null,Downloaded by: null,Prevalence: Reputation was not used in this detection.,Confidence: Reputation was not used in this detection.,URL Tracking Status: Off,,First Seen: Reputation was not used in this detection.,Sensitivity: Low,MDS,Application hash: ,Hash type: SHA1,Company name: ,Application name: ,Application version: ,Application type: -1,File size (bytes): 0,Category set: Security risk,Category type: UNKNOWN&lt;/P&gt;

&lt;P&gt;Extracted values: - &lt;BR /&gt;
user = 12345678&lt;BR /&gt;
user= "ABCD, XYZ {FGH}"&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 12:59:43 GMT</pubDate>
    <dc:creator>sjangampeta</dc:creator>
    <dc:date>2020-09-29T12:59:43Z</dc:date>
    <item>
      <title>Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320470#M4454</link>
      <description>&lt;P&gt;Need help in removing double quotes from extracted field value.&lt;/P&gt;

&lt;P&gt;EVAL-user = nullif(replace(user, "[^:]+:\s*(.*|\w+\,\s\w+\s{\w+})", "\1"),"")&lt;/P&gt;

&lt;P&gt;Sample Log:&lt;BR /&gt;
2017-02-12 14:02:05,Virus found,Source: Scheduled Scan,Risk name: OSX.Trojan.Gen,Occurrences: 1,/Users/71071190/Downloads/archive_manager.dmg,'',Actual action: Deleted,Requested action: Deleted,Secondary action: Deleted,Event time: 2017-02-08 22:38:17,Inserted: 2017-02-12 20:02:05,End: 2017-02-08 22:38:17,Last update time: 2017-02-12 20:02:05,Domain: North America,Group: My Company\North America\Workstations\Macs,User: "ABCD, XYZ {FGH}",Source computer: ,Source IP: ,Disposition: Good,Download site: null,Web domain: null,Downloaded by: null,Prevalence: Reputation was not used in this detection.,Confidence: Reputation was not used in this detection.,URL Tracking Status: Off,,First Seen: Reputation was not used in this detection.,Sensitivity: Low,MDS,Application hash: ,Hash type: SHA1,Company name: ,Application name: ,Application version: ,Application type: -1,File size (bytes): 0,Category set: Security risk,Category type: UNKNOWN&lt;BR /&gt;
2017-02-12 14:02:05,Virus found,Source: Scheduled Scan,Risk name: OSX.Trojan.Gen,Occurrences: 1,/Users/71071190/Downloads/archive_manager.dmg,'',Actual action: Deleted,Requested action: Deleted,Secondary action: Deleted,Event time: 2017-02-08 22:38:17,Inserted: 2017-02-12 20:02:05,End: 2017-02-08 22:38:17,Last update time: 2017-02-12 20:02:05,Domain: North America,Group: My Company\North America\Workstations\Macs,User: 12345678,Source computer: ,Source IP: ,Disposition: Good,Download site: null,Web domain: null,Downloaded by: null,Prevalence: Reputation was not used in this detection.,Confidence: Reputation was not used in this detection.,URL Tracking Status: Off,,First Seen: Reputation was not used in this detection.,Sensitivity: Low,MDS,Application hash: ,Hash type: SHA1,Company name: ,Application name: ,Application version: ,Application type: -1,File size (bytes): 0,Category set: Security risk,Category type: UNKNOWN&lt;/P&gt;

&lt;P&gt;Extracted values: - &lt;BR /&gt;
user = 12345678&lt;BR /&gt;
user= "ABCD, XYZ {FGH}"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320470#M4454</guid>
      <dc:creator>sjangampeta</dc:creator>
      <dc:date>2020-09-29T12:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320471#M4455</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rex field=user mode=sed "s/\"/ /g"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 Feb 2017 18:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320471#M4455</guid>
      <dc:creator>adayton20</dc:creator>
      <dc:date>2017-02-20T18:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320472#M4456</link>
      <description>&lt;P&gt;Thank you rex works. &lt;BR /&gt;
But we don't want to add during search time.&lt;/P&gt;

&lt;P&gt;Can I update anything in below calculated field?&lt;BR /&gt;
EVAL-user = nullif(replace(user, "[^:]+:\s*(.*|\w+\,\s\w+\s{\w+})", "\1"),"")&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320472#M4456</guid>
      <dc:creator>sjangampeta</dc:creator>
      <dc:date>2020-09-29T12:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320473#M4457</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EVAL-user=replace(user, "\"", "")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 Feb 2017 19:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320473#M4457</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-20T19:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320474#M4458</link>
      <description>&lt;P&gt;since we already have existing eval-user, where can i add this  "\"", ""  regex ?&lt;/P&gt;

&lt;P&gt;EVAL-user = nullif(replace(user, "[^:]+:\s*(.*|\w+\,\s\w+\s{\w+})", "\1"),"")&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320474#M4458</guid>
      <dc:creator>sjangampeta</dc:creator>
      <dc:date>2020-09-29T12:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320475#M4459</link>
      <description>&lt;P&gt;You can do 2 passes; put mine after the original.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 20:14:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320475#M4459</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-20T20:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320476#M4460</link>
      <description>&lt;P&gt;Tried this, but it fails .new user value "ABCD, XYZ {FGH}"s/"/ /g&lt;/P&gt;

&lt;P&gt;nullif(replace(user, "[^:]+:\s*(.*|\w+\,\s\w+\s{\w+})\"?", "s/\"/ /g\1"),"")&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320476#M4460</guid>
      <dc:creator>sjangampeta</dc:creator>
      <dc:date>2020-09-29T12:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320477#M4461</link>
      <description>&lt;P&gt;Why not just do a search time field extraction like this. &lt;/P&gt;

&lt;P&gt;props.conf on search head&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yoursourcetype]
EXTRACT-userfield = ,User:\s+\"*(?&amp;lt;user&amp;gt;.+)\"*,Source computer
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;See regex101 page for validation of regex&lt;BR /&gt;
&lt;A href="https://regex101.com/r/6e4pdb/1"&gt;https://regex101.com/r/6e4pdb/1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 20:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320477#M4461</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-20T20:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320478#M4462</link>
      <description>&lt;P&gt;may i know what I'm missing ? &lt;BR /&gt;
nullif(replace(user, "[^:]+:\s*(.*|\w+\,\s\w+\s{\w+})\"?", "s/\"/ /g\1"),"")&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:00:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320478#M4462</guid>
      <dc:creator>sjangampeta</dc:creator>
      <dc:date>2020-09-29T13:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Regex Help</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320479#M4463</link>
      <description>&lt;P&gt;our requirement was to update above eval function, so it can extract all user fields. they don't want to add search time field extraction&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 15:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Regex-Help/m-p/320479#M4463</guid>
      <dc:creator>sjangampeta</dc:creator>
      <dc:date>2017-02-21T15:51:42Z</dc:date>
    </item>
  </channel>
</rss>

