<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need help with  Regex in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/625942#M9196</link>
    <description>&lt;P&gt;Need help with Regex&lt;/P&gt;&lt;P&gt;field ------------------------feildvalue&lt;/P&gt;&lt;P&gt;servername ----------&amp;nbsp;xtestf100s&lt;/P&gt;&lt;P&gt;log_level--------------INFO OR error or warning&lt;/P&gt;&lt;P&gt;message ------------ anything from gofer till end&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [INFO][worker-0] gofer.messaging.adapter.connect:28 - connecting: proton+amqps://xtest123s.pharma.aventis.com:5647&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [INFO][worker-0] gofer.messaging.adapter.proton.connection:87 - open: URL: amqps://xtest123s.pharma.aventis.com:5647|SSL: ca: /etc/rhsm/ca/katello-default-ca.pem|key: None|certificate: /etc/pki/consumer/bundle.pem|host-validation: None&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [ERROR][worker-0] gofer.messaging.adapter.connect:33 - connect: proton+amqps://xtest123s.pharma.aventis.com:5647, failed: Connection amqps://xtest123s.pharma.aventis.com:5647 disconnected: Condition('proton.pythonio', 'Connection refused to all addresses')&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [INFO][worker-0] gofer.messaging.adapter.connect:35 - retry in 106 seconds&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566412): avc: denied { read } for pid=75981 comm="ip" name="libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566413): avc: denied { open } for pid=75981 comm="ip" path="/opt/commvault/Base64/libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566414): avc: denied { getattr } for pid=75981 comm="ip" path="/opt/commvault/Base64/libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566415): avc: denied { execute } for pid=75981 comm="ip" path="/opt/commvault/Base64/libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:51:43 xtestf100s kernel: type=1400 audit(1672714303.392:566416): avc: denied { read } for pid=77988 comm="ip" name="Base" dev="dm-13" ino=116 scontext=system_u:system_r:ifconfig_t:s0 tcontext=unconfined_u:object_r:unlabeled_t:s0 tclass=lnk_file permissive=1&lt;BR /&gt;Jan 3 03:51:43 xtestf100s kernel: type=1400 audit(1672714303.392:566417): avc: denied { read } for pid=77988 comm="ip" name="libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2023 05:34:25 GMT</pubDate>
    <dc:creator>AK_Splunk</dc:creator>
    <dc:date>2023-01-05T05:34:25Z</dc:date>
    <item>
      <title>Need help with  Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/625942#M9196</link>
      <description>&lt;P&gt;Need help with Regex&lt;/P&gt;&lt;P&gt;field ------------------------feildvalue&lt;/P&gt;&lt;P&gt;servername ----------&amp;nbsp;xtestf100s&lt;/P&gt;&lt;P&gt;log_level--------------INFO OR error or warning&lt;/P&gt;&lt;P&gt;message ------------ anything from gofer till end&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [INFO][worker-0] gofer.messaging.adapter.connect:28 - connecting: proton+amqps://xtest123s.pharma.aventis.com:5647&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [INFO][worker-0] gofer.messaging.adapter.proton.connection:87 - open: URL: amqps://xtest123s.pharma.aventis.com:5647|SSL: ca: /etc/rhsm/ca/katello-default-ca.pem|key: None|certificate: /etc/pki/consumer/bundle.pem|host-validation: None&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [ERROR][worker-0] gofer.messaging.adapter.connect:33 - connect: proton+amqps://xtest123s.pharma.aventis.com:5647, failed: Connection amqps://xtest123s.pharma.aventis.com:5647 disconnected: Condition('proton.pythonio', 'Connection refused to all addresses')&lt;BR /&gt;Jan 3 03:50:38 xtestf100s goferd: [INFO][worker-0] gofer.messaging.adapter.connect:35 - retry in 106 seconds&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566412): avc: denied { read } for pid=75981 comm="ip" name="libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566413): avc: denied { open } for pid=75981 comm="ip" path="/opt/commvault/Base64/libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566414): avc: denied { getattr } for pid=75981 comm="ip" path="/opt/commvault/Base64/libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:50:54 xtestf100s kernel: type=1400 audit(1672714254.276:566415): avc: denied { execute } for pid=75981 comm="ip" path="/opt/commvault/Base64/libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;Jan 3 03:51:43 xtestf100s kernel: type=1400 audit(1672714303.392:566416): avc: denied { read } for pid=77988 comm="ip" name="Base" dev="dm-13" ino=116 scontext=system_u:system_r:ifconfig_t:s0 tcontext=unconfined_u:object_r:unlabeled_t:s0 tclass=lnk_file permissive=1&lt;BR /&gt;Jan 3 03:51:43 xtestf100s kernel: type=1400 audit(1672714303.392:566417): avc: denied { read } for pid=77988 comm="ip" name="libCvDllFilter.so" dev="dm-13" ino=393745 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file permissive=1&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 05:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/625942#M9196</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2023-01-05T05:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with  Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/625953#M9197</link>
      <description>&lt;P&gt;Again - use preformatted style or code block to include blocks of text which should not be "massacred" by the browser. (like event samples).&lt;/P&gt;&lt;P&gt;The hostname extraction should work pretty well with standard transform "syslog-host". And it should be done in index-time since you probably want to have this as host field. Otherwise, if you really only need it as search-time extraction,&amp;nbsp; just copy the regex from the syslog-host transform.&lt;/P&gt;&lt;P&gt;For log level... the most obvious one that comes to mind is&lt;/P&gt;&lt;PRE&gt;\[(?&amp;lt;log_level&amp;gt;INFO|ERROR|WARNING)\]&lt;/PRE&gt;&lt;P&gt;But this might not be the best idea depending on how you want it anchored within the event.&lt;/P&gt;&lt;P&gt;For message - with your definition - it would be&lt;/P&gt;&lt;PRE&gt;(?&amp;lt;message&amp;gt;goferd.*)&lt;/PRE&gt;&lt;P&gt;But that's probably _not_ what you want. And while Splunk can sometimes optimize some things relatively well, you might want to rewrite multiple separate extractions into a single regex with multiple capturing groups.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 08:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/625953#M9197</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-05T08:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with  Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/625955#M9198</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in your regex there are two different logs, if you want to take as message from "gofer" to the end of row you can use the following regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
|c rex "^(?&amp;lt;timestamp&amp;gt;\w+ \d+ \d+:\d+:\d*)\s+(?&amp;lt;servername&amp;gt;\w+)[^\[]+\[(?&amp;lt;log_level&amp;gt;[^\]]+)\][^\]]+\]\s+(?&amp;lt;message&amp;gt;.*)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/tQJVAm/1" target="_blank"&gt;https://regex101.com/r/tQJVAm/1&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;about the second part of logs, what do you want to extract?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 08:23:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/625955#M9198</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-05T08:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with  Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/626122#M9202</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Thanks for your response but can you guide how to send sample data by using&amp;nbsp;&lt;SPAN&gt;preformatted style or code block&amp;nbsp;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 09:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/626122#M9202</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2023-01-06T09:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with  Regex</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/626131#M9203</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to send code or sample data use the "Insert/Edit code sample" ("&amp;lt;/&amp;gt;") button.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 10:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Need-help-with-Regex/m-p/626131#M9203</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-06T10:46:41Z</dc:date>
    </item>
  </channel>
</rss>

