<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex question extracting user from webserver log in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50248#M12070</link>
    <description>&lt;P&gt;Finally got one working as I want:&lt;/P&gt;

&lt;P&gt;(?:\"(?&lt;USER&gt;[^\"]+)\"|(?&lt;USER&gt;[^\s]+))&lt;/USER&gt;&lt;/USER&gt;&lt;/P&gt;

&lt;P&gt;Or not, RegExr and Expresso works ok with this, but Splunk Rex command fails due to multiple &lt;USER&gt; blocks.&lt;/USER&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 11 May 2012 20:19:41 GMT</pubDate>
    <dc:creator>mikelanghorst</dc:creator>
    <dc:date>2012-05-11T20:19:41Z</dc:date>
    <item>
      <title>Regex question extracting user from webserver log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50247#M12069</link>
      <description>&lt;P&gt;For this sample data:&lt;BR /&gt;
172.21.174.78 - "/dc=com/dc=caiso/OU=people/CN=Bob User" [11/May/2012:11:27:40 -0700] "POST /APP/ClientWebService HTTP/1.0" 200 439 "-" "Mozilla/3.0 (compatible; Indy Library)"&lt;BR /&gt;
172.21.174.78 - mlanghor [11/May/2012:11:27:40 -0700] "POST /APP/ClientWebService HTTP/1.0" 200 439 "-" "Mozilla/3.0 (compatible; Indy Library)"&lt;BR /&gt;
172.21.174.78 - - [11/May/2012:11:27:40 -0700] "POST /APP/ClientWebService HTTP/1.0" 200 439 "-" "Mozilla/3.0 (compatible; Indy Library)"&lt;/P&gt;

&lt;P&gt;For some of our webserver logs, we are logging the DN from the user certificate with %{SSL_CLIENT_S_DN}x.&lt;/P&gt;

&lt;P&gt;The default extraction for user is [[nspaces:user], so essentially (?&lt;USER&gt;[^\s]+).&lt;/USER&gt;&lt;/P&gt;

&lt;P&gt;In trying to extract the different variations for the user field I came up with:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;(?&amp;lt;user&amp;gt;([^\"\s]+|\"[^\"]+\"))&lt;/CODE&gt;&lt;BR /&gt;
But that includes the " as part of the field.  I'm haven't been able to come up with a regex that"&lt;BR /&gt;
when the first character is a " grab everything but not including the "'s, otherwise, grab everything till the next space.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50247#M12069</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Regex question extracting user from webserver log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50248#M12070</link>
      <description>&lt;P&gt;Finally got one working as I want:&lt;/P&gt;

&lt;P&gt;(?:\"(?&lt;USER&gt;[^\"]+)\"|(?&lt;USER&gt;[^\s]+))&lt;/USER&gt;&lt;/USER&gt;&lt;/P&gt;

&lt;P&gt;Or not, RegExr and Expresso works ok with this, but Splunk Rex command fails due to multiple &lt;USER&gt; blocks.&lt;/USER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2012 20:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50248#M12070</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-05-11T20:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Regex question extracting user from webserver log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50249#M12071</link>
      <description>&lt;P&gt;while regexr accepts it just fine, passing this to rex fails with:&lt;BR /&gt;
Error in 'rex' command: Encountered the following error while compiling the regex '(?:(?:"(?&lt;USER&gt;[^"]+)")|(?&lt;USER&gt;[^\s]+))': Regex: two named subpatterns have the same name&lt;/USER&gt;&lt;/USER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2012 20:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50249#M12071</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-05-11T20:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Regex question extracting user from webserver log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50250#M12072</link>
      <description>&lt;P&gt;Would this work? Unescape the double quotes if needed.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;^\S+\s+\S+\s+\"?(?&amp;lt;user&amp;gt;(?:([^\"]+)\"\s|([\S]+)\s+))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;

&lt;P&gt;UPDATE:&lt;/P&gt;

&lt;P&gt;Played around a little more with RegExr, and this looks good in there anyway (capture group 1 is OK). &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;^\S+\s+\S+\s+\"?(?&amp;lt;user&amp;gt;(?:(([^\"]+))|([\S]+)\s+))(?:\"\s\[|\s\[)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Wondering if it works,&lt;/P&gt;

&lt;P&gt;/Kristian&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2012 21:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50250#M12072</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-05-11T21:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Regex question extracting user from webserver log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50251#M12073</link>
      <description>&lt;P&gt;Seems closer, but it's retaining the closing quote.&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2012 21:50:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50251#M12073</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-05-11T21:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Regex question extracting user from webserver log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50252#M12074</link>
      <description>&lt;P&gt;You need to work with lookbehinds.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;(?&amp;lt;user&amp;gt;(?&amp;lt;=\")[^\"]+|(?&amp;lt;!\")[^\s\"]+)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2014 06:13:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-question-extracting-user-from-webserver-log/m-p/50252#M12074</guid>
      <dc:creator>danielschroeder</dc:creator>
      <dc:date>2014-05-13T06:13:45Z</dc:date>
    </item>
  </channel>
</rss>

