<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex to extract for fqdn in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561991#M100098</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp; - Thanks for the quick reply. &amp;nbsp;No, I wasn't able to get that to work. &amp;nbsp;Basically what I am trying to do is extract the FQDN hostname so that I can use it in my input.conf file.&lt;/P&gt;&lt;P&gt;Similar to what this guy is doing:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Help-extracting-hostname-with-host-regex-from-path/m-p/478981" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Help-extracting-hostname-with-host-regex-from-path/m-p/478981&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Aug 2021 01:26:26 GMT</pubDate>
    <dc:creator>jaydee12</dc:creator>
    <dc:date>2021-08-04T01:26:26Z</dc:date>
    <item>
      <title>Regex to extract for fqdn</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561982#M100094</link>
      <description>&lt;P&gt;Hi - Was looking for some assistance in extracting the FQDNs from the paths below:&lt;/P&gt;&lt;P&gt;/var/log/remote/ldap.inftech.net/2021-08-03/auth.log&lt;BR /&gt;/var/log/remote/web-proxy-01.int.inftech.net/2021-08-03/proxy.log&lt;BR /&gt;/var/log/remote/ns01.inftech.net/2021-08-03/named.log&lt;/P&gt;&lt;P&gt;Regex isn't my strongest area, and one of the domains has an additional level, which makes it that much harder for me.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 00:57:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561982#M100094</guid>
      <dc:creator>jaydee12</dc:creator>
      <dc:date>2021-08-04T00:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to extract for fqdn</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561986#M100095</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237101"&gt;@jaydee12&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try this,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search_goes_here&amp;gt;
| rex field=&amp;lt;your_field_name&amp;gt; "var\/log\/remote\/(?&amp;lt;fqdn&amp;gt;.+?)\/"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 01:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561986#M100095</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-04T01:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to extract for fqdn</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561991#M100098</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp; - Thanks for the quick reply. &amp;nbsp;No, I wasn't able to get that to work. &amp;nbsp;Basically what I am trying to do is extract the FQDN hostname so that I can use it in my input.conf file.&lt;/P&gt;&lt;P&gt;Similar to what this guy is doing:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Help-extracting-hostname-with-host-regex-from-path/m-p/478981" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Help-extracting-hostname-with-host-regex-from-path/m-p/478981&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 01:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561991#M100098</guid>
      <dc:creator>jaydee12</dc:creator>
      <dc:date>2021-08-04T01:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to extract for fqdn</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561997#M100099</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237101"&gt;@jaydee12&lt;/a&gt;&amp;nbsp; Rex looks fine see below. commands before | rex for testing you shall replace with your own search.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venkatasri_0-1628041378654.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15416i8DF2E06ED708049C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venkatasri_0-1628041378654.png" alt="venkatasri_0-1628041378654.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 01:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561997#M100099</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-04T01:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to extract for fqdn</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561999#M100101</link>
      <description>&lt;P&gt;Yes, you are correct...that did work, &amp;nbsp;Greatly appreciate your help!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 02:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Regex-to-extract-for-fqdn/m-p/561999#M100101</guid>
      <dc:creator>jaydee12</dc:creator>
      <dc:date>2021-08-04T02:05:30Z</dc:date>
    </item>
  </channel>
</rss>

