<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: regex help with existing regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403681#M116807</link>
    <description>&lt;P&gt;&lt;A href="https://rubular.com/r/vJiAT83eSPmWtf"&gt;https://rubular.com/r/vJiAT83eSPmWtf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2019 20:39:39 GMT</pubDate>
    <dc:creator>fisuser1</dc:creator>
    <dc:date>2019-05-30T20:39:39Z</dc:date>
    <item>
      <title>regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403670#M116796</link>
      <description>&lt;P&gt;have a business area that changed some of their log format which broke my existing regex and having a hard time matching response code. seems my existing regex is pulling two matches from each event. (matching &lt;EM&gt;"fromIndex=150"&lt;/EM&gt; or &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;*"fromIndex=100"* also in the event) any suggestions to edit this? 

Existing regex: (working before log format change)
\b(?&amp;lt;**http_status**&amp;gt;\d{3}) \d

_raw data:
2019-05-30 17:52:15 127.0.0.1 GET /api/accounts/19006/account-history timePeriod=&amp;amp;type=&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1123 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"061120534","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:67.0)+Gecko/20100101+Firefox/67.0 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 3531 127.0.0.1 

2019-05-30 17:52:05 127.0.0.1 GET /api/accounts/67343/account-history timePeriod=7&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1124 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"061120686","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 875 127.0.0.1 

2019-05-30 17:52:03 127.0.0.1 GET /api/accounts/46850/account-history timePeriod=&amp;amp;type=&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1120 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"091302966","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(Linux;+Android+7.0;+SM-G928V)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/73.0.3683.90+Mobile+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 3578 127.0.0.1 

2019-05-30 17:51:51 127.0.0.1 GET /103103985/api/accounts/33098/account-history timePeriod=&amp;amp;type=&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 80 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"103103985","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(Windows+NT+10.0;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko &lt;A href="https://my.bankingsite.com/103103985/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/103103985/ORUI/&lt;/A&gt; **200** 0 0 562 127.0.0.1 

2019-05-30 17:51:50 127.0.0.1 GET /api/accounts/14342/account-history timePeriod=03/22/2019,05/30/2019&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1111 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"061120806","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:61.0)+Gecko/20100101+Firefox/61.0 &lt;A href="https://my.bankingsite.com/ORUI/index.html" target="test_blank"&gt;https://my.bankingsite.com/ORUI/index.html&lt;/A&gt; 200 0 0 1718 127.0.0.1 

2019-05-30 17:51:47 127.0.0.1 GET /api/accounts/128235/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1101 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"053102586","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 484 127.0.0.1 

2019-05-30 17:51:43 127.0.0.1 GET /api/accounts/57435/account-history timePeriod=7&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1112 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"064106775","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 1125 127.0.0.1 

2019-05-30 17:51:41 127.0.0.1 GET /api/accounts/66752/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1150 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"221971015","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 187 127.0.0.1 

2019-05-30 17:51:35 127.0.0.1 GET /api/accounts/290903/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1127 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"102000966","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 1562 127.0.0.1 

2019-05-30 17:51:32 127.0.0.1 GET /api/accounts/36874/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1107 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"063114030","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 875 127.0.0.1 

2019-05-30 17:51:30 127.0.0.1 GET /api/accounts/24299/account-history timePeriod=&amp;amp;type=&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1135 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"111908965","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 6703 127.0.0.1 

2019-05-30 17:51:17 127.0.0.1 GET /api/accounts/389912/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1127 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"102000966","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 765 127.0.0.1 

2019-05-30 17:51:01 127.0.0.1 GET /pahranagatvalleyfcu/api/accounts/4058/account-history timePeriod=09/27/2016,05/30/2019&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;*startfromIndex=100* 1101 {"{“UserId”:crazy_carl,”Username”:”foo”,"Realm":"003381.MERCURY","sessionTimeout":"20","ipAddress”:”127.1.1.1”} 127.0.0.1  Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:61.0)+Gecko/20100101+Firefox/61.0 &lt;A href="https://my.bankingsite.com/PahranagatValleyFCU/ORUI/index.html" target="test_blank"&gt;https://my.bankingsite.com/PahranagatValleyFCU/ORUI/index.html&lt;/A&gt; **200** 0 0 6546 127.0.0.1 

2019-05-30 18:03:26 127.0.0.1 GET /api/system/logoff - 1118 - 127.0.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_14_4)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1+Safari/605.1.15 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **401** 0 0 0 127.0.0.1

2019-05-30 18:03:26 127.0.0.1 GET /api/personalfinance/ widgetName=mini_spending_widget&amp;amp;sync=true 1118 - 127.0.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_14_4)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1+Safari/605.1.15 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **401** 0 0 0 127.0.0.1

2019-05-30 18:03:26 127.0.0.1 GET /api/system/logoff - 1118 - 127.0.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_14_4)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1+Safari/605.1.15 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **401** 0 0 15 127.0.0.1

2019-05-30 18:03:26 127.0.0.1 GET /api/system/logoff - 1118 - 127.0.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_14_4)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1+Safari/605.1.15 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **401** 0 0 0 127.0.0.1

2019-05-30 18:03:26 127.0.0.1 GET /api/personalfinance/ widgetName=mini_spending_widget&amp;amp;sync=true 1118 - 127.0.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_14_4)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1+Safari/605.1.15 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **401** 0 0 15 127.0.0.1

2019-05-30 18:03:26 127.0.0.1 GET /api/system/logoff - 1118 - 127.0.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_14_4)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1+Safari/605.1.15 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **401** 0 0 0 127.0.0.1

2019-05-30 18:03:26 127.0.0.1 GET /CommCUofNewMilford/api/users/22/getholdamount accountId=2175 1101 {"UserId”:crazy_carl,”Username”:”foo”,”Realm":"003042.MERCURY","sessionTimeout":"20","ipAddress":"107.77.224.32"} 127.0.0.1 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+12_2+like+Mac+OS+X)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1+Mobile/15E148+Safari/604.1 &lt;A href="https://my.bankingsite.com/CommCUofNewMilford/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/CommCUofNewMilford/ORUI/&lt;/A&gt; **200** 0 0 109 127.0.0.1

2019-05-30 18:03:25 127.0.0.1 GET /api/users/22/accounts assetSortOrder=ASC&amp;amp;assetDefaultSortColumn=accountName&amp;amp;investmentSortOrder=ASC&amp;amp;investmentDefaultSortColumn=accountName&amp;amp;liabilitiesortOrder=ASC&amp;amp;liabilitiesDefaultSortColumn=accountName&amp;amp;externalSortOrder=ASC&amp;amp;externalDefaultSortColumn=accountName&amp;amp;ccSortOrder=ASC&amp;amp;ccDefaultSortColumn=accountName 1101 {"UserId”:crazy_carl,”Username”:”foo”,”Realm":"111906271","sessionTimeout":"20","ipAddress":"127.0.0.1"} 127.0.0.1 Mozilla/5.0+(Linux;+Android+9;+SM-G955U)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.157+Mobile+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 140 127.0.0.1

2019-05-30 18:03:25 127.0.0.1 GET /login.aspx ReturnUrl=%2fORUI%2f 1101 - 127.0.0.1 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+12_3_1+like+Mac+OS+X)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.1.1+Mobile/15E148+Safari/604.1 - **200** 0 0 46 172.58.99.130

2019-05-30 18:03:25 127.0.0.1 GET /api/users/22/scorecardrewards - 1101 {"UserId”:crazy_carl,”Username”:”foo”,”Realm":"111906271","sessionTimeout":"20","ipAddress":"127.0.0.1"} 127.0.0.1 Mozilla/5.0+(Linux;+Android+9;+SM-G955U)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.157+Mobile+Safari/537.36 &lt;A href="https://my.bankingsite.com/ORUI/" target="test_blank"&gt;https://my.bankingsite.com/ORUI/&lt;/A&gt; **200** 0 0 46 127.0.0.1

2019-05-30 18:03:25 127.0.0.1 GET /ORUI/index.html - 1101 {"UserId”:crazy_carl,”Username”:”foo”,”Realm":"111906271","sessionTimeout":"20","ipAddress":"127.0.0.1 "} 127.0.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 &lt;A href="https://my.bankingsite.com/PassMarkRecognizedAdv.aspx?qs=b2TU7c2wr8E0dfptJiVc6osqODJNVVaa6UZusUsRdZI%3d" target="test_blank"&gt;https://my.bankingsite.com/PassMarkRecognizedAdv.aspx?qs=b2TU7c2wr8E0dfptJiVc6osqODJNVVaa6UZusUsRdZI%3d&lt;/A&gt; **200** 0 0 125 127.0.0.1

2019-05-30 18:03:25 127.0.0.1 GET /OOBChallenge.aspx qs=cUlHrH9oGju91rnRg%2bOmkzrLhg8Oc0ZMSvVHZDwpaoNAhY0dPG6o3WXkCMUZMARx61iChJjKqmntkcKCmNEX9oD2KDmMage%2fb2TU7c2wr8E0dfptJiVc6osqODJNVVaan3drqxuh3WzZy%2fva1rs6RM9OaC59wRrRZ2yA%2bDcWz7lmJSZPd2bHwWdceDRZ9bE2QNZL%2f5%2fuohrofoZvlVaPJA%3d%3d 1101 - 127.0.0.1 Mozilla/5.0+(Windows+NT+6.1;+Trident/7.0;+rv:11.0)+like+Gecko &lt;A href="https://my.bankingsite.com/SignOn.aspx?qs=nLl1ZWczEjHofoZvlVaPJA%3d%3d" target="test_blank"&gt;https://my.bankingsite.com/SignOn.aspx?qs=nLl1ZWczEjHofoZvlVaPJA%3d%3d&lt;/A&gt; **200** 0 0 453 127.0.0.1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 30 May 2019 18:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403670#M116796</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-30T18:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403671#M116797</link>
      <description>&lt;P&gt;I think this is what you want....&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;        \*\*(?&amp;lt;http_status&amp;gt;\d{3})\*\*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 30 May 2019 18:54:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403671#M116797</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2019-05-30T18:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403672#M116798</link>
      <description>&lt;P&gt;Having asterisks around the staus complicated things by a bit, it is not good practice to use asterisks like that.&lt;/P&gt;

&lt;P&gt;This works :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[\*]{2}(?&amp;lt;http_status&amp;gt;\d{3})[\*]{2}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;it doesnt work on line 15 as that is formatted differently than others, is this a mistake or will these events also be in the sample? In that case the regex will need to be slightly different&lt;/P&gt;

&lt;P&gt;For confirming and working on regex, I'd recommend this site:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://rubular.com/"&gt;https://rubular.com/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;paste the sample events into the test string area and the regex into the reg expression editor and see the magic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 19:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403672#M116798</guid>
      <dc:creator>martinpu</dc:creator>
      <dc:date>2019-05-30T19:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403673#M116799</link>
      <description>&lt;P&gt;thx for the response, but this doesn't seem to extract any field, http_status, in from the raw data&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 19:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403673#M116799</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-30T19:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403674#M116800</link>
      <description>&lt;P&gt;How are you trying to use the regex? Are you trying to use it in SPL or as part of a conf? Can you better define what you are trying to collect? The question describes trying to collect the "fromIndex=" value but the regex looks like it is trying to extract the http status value. My suggestion was for the http status code.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 20:21:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403674#M116800</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2019-05-30T20:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403675#M116801</link>
      <description>&lt;P&gt;Thanks for the response &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163010"&gt;@martinpu&lt;/a&gt;.  actually, for whatever reason, the answers.splunk.com format added that.  there are no ** around the status codes in the logs.  These are IIS logs.  Not sure why the format of this page added them.   Pasting a few examples again. &lt;/P&gt;

&lt;P&gt;2019-05-30 11:26:48 127.0.0.1 GET /javascript/MenuDropItems.js v=1801 1101 - 10.237.0.43 Mozilla/5.0+(Linux;+Android+8.0.0;+SM-G930T)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.157+Mobile+Safari/537.36 &lt;A href="https://online.com/PassMarkRecognizedAdv.aspx?qs=b2TU7c2wr8E0dfptJiVc6osqODJNVVaa6UZusUsRdZI%3d" target="_blank"&gt;https://online.com/PassMarkRecognizedAdv.aspx?qs=b2TU7c2wr8E0dfptJiVc6osqODJNVVaa6UZusUsRdZI%3d&lt;/A&gt; 200 0 0 0 127.0.0.1&lt;/P&gt;

&lt;P&gt;2019-05-30 10:56:06 127.0.0.1 GET /api/accounts/3448122/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;startfromIndex=150 1101 {"UserId":carl,"Username":"mr_blah","Realm":"111906271","sessionTimeout":"20","ipAddress":"127.0.0.1"} 127.0.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/59.0.3071.115+Safari/537.36 &lt;A href="https://online.com/ORUI/" target="_blank"&gt;https://online.com/ORUI/&lt;/A&gt; 200 0 0 250 127.0.0.1&lt;/P&gt;

&lt;P&gt;2019-05-30 10:55:57 127.0.0.1 GET /064107994/api/accounts/17004/account-history timePeriod=03/01/2019,05/30/2019&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;startfromIndex=150 80 {"UserId":carl,"Username":"mr_blah","Realm":"064107994","sessionTimeout":"20","ipAddress":"127.0.0.1"} 127.0.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:61.0)+Gecko/20100101+Firefox/61.0 &lt;A href="https://www.banking.com/064107994/ORUI/index.html" target="_blank"&gt;https://www.banking.com/064107994/ORUI/index.html&lt;/A&gt; 200 0 0 1062 127.0.0.1&lt;/P&gt;

&lt;P&gt;2019-05-30 10:54:59 127.0.0.1 GET /api/accounts/55233/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;startfromIndex=150 1120 {"UserId":carl,"Username":"mr_blah","Realm":"091302966","sessionTimeout":"20","ipAddress":"127.0.0.1"} 127.0.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/59.0.3071.115+Safari/537.36 &lt;A href="https://choicefinancialgroup.ebanking-services.com/ORUI/" target="_blank"&gt;https://choicefinancialgroup.ebanking-services.com/ORUI/&lt;/A&gt; 200 0 0 2375 127.0.0.1&lt;/P&gt;

&lt;P&gt;2019-05-30 10:54:54 10.237.66.52 GET /api/accounts/69173/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;startfromIndex=150 1150 {"UserId":carl,"Username":"mr_blah","Realm":"221971015","sessionTimeout":"20","ipAddress":"127.0.0.1"} 127.0.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/43.0.2357.125+Safari/537.36 &lt;A href="https://onlinebanking.rhinebeckbank.com/ORUI/" target="_blank"&gt;https://onlinebanking.rhinebeckbank.com/ORUI/&lt;/A&gt; 200 0 0 734 127.0.0.1&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:45:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403675#M116801</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2020-09-30T00:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403676#M116802</link>
      <description>&lt;P&gt;this will be done via props.  trying to match on the http_status value only, ie 200 or 401 in the raw data provided.  the current regex I provided is matching on both "fromIndex=" AND http status fields after the application team changed the log format. &lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 20:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403676#M116802</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-30T20:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403677#M116803</link>
      <description>&lt;P&gt;another example:&lt;/P&gt;

&lt;P&gt;2019-05-30 10:56:06 127.0.0.1 GET /api/accounts/3448122/account-history timePeriod=1&amp;amp;type=1&amp;amp;amount=&amp;amp;check=&amp;amp;description=&amp;amp;startfromIndex=150 1101 {"UserId":9999999,"Username":"mr_blah","Realm":"111906271","sessionTimeout":"20","ipAddress":"127.0.0.1"} 127.0.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/59.0.3071.115+Safari/537.36 &lt;A href="https://online.com/ORUI/" target="_blank"&gt;https://online.com/ORUI/&lt;/A&gt; &lt;STRONG&gt;200&lt;/STRONG&gt; 0 0 250 127.0.0.1&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403677#M116803</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2020-09-30T00:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403678#M116804</link>
      <description>&lt;P&gt;this was the working regex before they changed format&lt;/P&gt;

&lt;P&gt;\b(?&amp;lt;&lt;STRONG&gt;http_status&lt;/STRONG&gt;&amp;gt;\d{3}) \d&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 20:37:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403678#M116804</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-30T20:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403679#M116805</link>
      <description>&lt;P&gt;working regex before log format change, which was extracting http_status&lt;/P&gt;

&lt;P&gt;\b(?&amp;lt;&lt;STRONG&gt;http_status&lt;/STRONG&gt;&amp;gt;\d{3}) \d&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 20:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403679#M116805</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-30T20:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403680#M116806</link>
      <description>&lt;P&gt;&lt;A href="https://rubular.com/r/vJiAT83eSPmWtf"&gt;https://rubular.com/r/vJiAT83eSPmWtf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 20:39:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403680#M116806</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-30T20:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403681#M116807</link>
      <description>&lt;P&gt;&lt;A href="https://rubular.com/r/vJiAT83eSPmWtf"&gt;https://rubular.com/r/vJiAT83eSPmWtf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 20:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403681#M116807</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-30T20:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403682#M116808</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;http([^\s]+) (?&amp;lt;**http_status**&amp;gt;\d{3}) \d
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;After http matches any word until space then takes 3 digits if those are followed by a space and a digit, I think it should cover everything&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 21:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403682#M116808</guid>
      <dc:creator>martinpu</dc:creator>
      <dc:date>2019-05-30T21:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403683#M116809</link>
      <description>&lt;P&gt;&lt;A href="https://rubular.com/r/cNK8laTGhhCYAG"&gt;https://rubular.com/r/cNK8laTGhhCYAG&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 23:18:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403683#M116809</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2019-05-30T23:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403684#M116810</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;\b(?&amp;lt;http_status&amp;gt;\d{3})\s\d+\s\d+\s\d+\s\d+\.\d+\.\d+\.\d+
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 30 May 2019 23:19:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403684#M116810</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2019-05-30T23:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403685#M116811</link>
      <description>&lt;P&gt;That checks for all the fields to the end of the message, its ugly but got rid of false matches.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 23:19:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403685#M116811</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2019-05-30T23:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403686#M116812</link>
      <description>&lt;P&gt;thank you @mydog8it , it looks like this may have worked.  the log format is pretty inconsistent, so I do have the developers/admins fixing this, but it seems this is matching more accurately now.  thank you again for all the help!  &lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 11:14:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403686#M116812</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-31T11:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403687#M116813</link>
      <description>&lt;P&gt;thank you @martinpu, i tested this and seemed to extract properly.  I'll continue monitor the update I made (very inconsistent logs which the dev team is addressing) and refer to your extraction if necessary.  thanks again for all the help! &lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 11:17:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403687#M116813</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2019-05-31T11:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: regex help with existing regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403688#M116814</link>
      <description>&lt;P&gt;You're very welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Happy Splunking&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 20:06:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/regex-help-with-existing-regex/m-p/403688#M116814</guid>
      <dc:creator>martinpu</dc:creator>
      <dc:date>2019-05-31T20:06:10Z</dc:date>
    </item>
  </channel>
</rss>

