<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: negative regex in search command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56184#M13730</link>
    <description>&lt;P&gt;Thanks for your edit.&lt;/P&gt;

&lt;P&gt;My last question is about the way to encapsulate all the reg to build this graph :&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://img823.imageshack.us/img823/7216/capturemee.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;I have to match all the IP begining with 192 (dark green), all the IP without 192 (light green) and build a graph like this. &lt;BR /&gt;
But I think I can't with the "search NO ip=192.*" command because it filter at the end no?&lt;/P&gt;

&lt;P&gt;I would like if it's possible to do the 2 commands like : &lt;/P&gt;

&lt;P&gt;command01(only 192) AS inbound command02(only without 192) AS outbound | timechart ......&lt;/P&gt;

&lt;P&gt;Is it possible?&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2012 12:44:59 GMT</pubDate>
    <dc:creator>AdrienW</dc:creator>
    <dc:date>2012-01-23T12:44:59Z</dc:date>
    <item>
      <title>negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56177#M13723</link>
      <description>&lt;P&gt;Dear,&lt;/P&gt;

&lt;P&gt;I have some issue with a regular expression in a search command.&lt;BR /&gt;
I have in a log a field called "src" with some IP in value of this field.&lt;BR /&gt;
I succeeded to match the IP wich begin with 192 with this command :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rex .*nosrc=(?192\.\d+\.\d+\.\d+).*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now I would like to match all the IP that DOES NOT begin with 192. How do I can do?&lt;/P&gt;

&lt;P&gt;Is the "^" character recognised by Splunk?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 09:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56177#M13723</guid>
      <dc:creator>AdrienW</dc:creator>
      <dc:date>2012-01-23T09:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56178#M13724</link>
      <description>&lt;P&gt;It seems some of your text got lost in the formatting. I'm assuming your search looks something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex ".*nosrc=(?&amp;lt;somefieldname&amp;gt;192\.\d+\.\d+\.\d+).*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;First of all, you don't need the leading and trailing &lt;CODE&gt;.*&lt;/CODE&gt;. Splunk will match that automatically. Second, if all you need is a specific regex matching any IP numbers that do not begin with 192, this should work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "nosrc=(?&amp;lt;somefieldname&amp;gt;19[^2]\.\d+\.\d+\.\d+)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That said, the approach is kind of weird and it might be better to just match all IP's in general and instead apply this kind of filtering separately once the field has been extracted. My suggestion would be to do something like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "nosrc=(?&amp;lt;somefieldname&amp;gt;\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}) | search NOT somefieldname="192.*"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Jan 2012 09:53:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56178#M13724</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-01-23T09:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56179#M13725</link>
      <description>&lt;P&gt;I tried with your first answer : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="index" sourcetype="my_sourcetype" | rex "src=(?&amp;lt;ip&amp;gt;19[^2]\.\d+\.\d+\.\d+)" | stats count(ip) by ip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That doesn't match anything, but &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rex "src=(?&amp;lt;ip&amp;gt;192\.\d+\.\d+\.\d+)" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;return 192.XXX values.&lt;/P&gt;

&lt;P&gt;Do you know why?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 10:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56179#M13725</guid>
      <dc:creator>AdrienW</dc:creator>
      <dc:date>2012-01-23T10:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56180#M13726</link>
      <description>&lt;P&gt;Here is the return when I match all the IP of the field src on my index with the command : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;stats count(src) by src
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;IMG src="http://img197.imageshack.us/img197/9499/ipspf.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;When I use this command I got only 2 values returned :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rex "src=(?&amp;lt;ip&amp;gt;\d{3}\.\d{3}\.\d{3}\.\d{3})" | search NOT ip="192.*" | stats count(ip) by ip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;wich are : 109.202.232.150 // 169.254.144.215&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 10:19:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56180#M13726</guid>
      <dc:creator>AdrienW</dc:creator>
      <dc:date>2012-01-23T10:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56181#M13727</link>
      <description>&lt;P&gt;Because the regex is looking for anything that starts with a 19 but not 192. What I would do is probably rex all IP's and then use a pipe to where to filter out the 192 addresses&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 11:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56181#M13727</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-01-23T11:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56182#M13728</link>
      <description>&lt;P&gt;Oops! My regex was wrong. Editing my answer.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 11:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56182#M13728</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-01-23T11:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56183#M13729</link>
      <description>&lt;P&gt;Hah, I didn't even look at your final rex suggestion!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 12:34:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56183#M13729</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-01-23T12:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56184#M13730</link>
      <description>&lt;P&gt;Thanks for your edit.&lt;/P&gt;

&lt;P&gt;My last question is about the way to encapsulate all the reg to build this graph :&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://img823.imageshack.us/img823/7216/capturemee.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;I have to match all the IP begining with 192 (dark green), all the IP without 192 (light green) and build a graph like this. &lt;BR /&gt;
But I think I can't with the "search NO ip=192.*" command because it filter at the end no?&lt;/P&gt;

&lt;P&gt;I would like if it's possible to do the 2 commands like : &lt;/P&gt;

&lt;P&gt;command01(only 192) AS inbound command02(only without 192) AS outbound | timechart ......&lt;/P&gt;

&lt;P&gt;Is it possible?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 12:44:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56184#M13730</guid>
      <dc:creator>AdrienW</dc:creator>
      <dc:date>2012-01-23T12:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56185#M13731</link>
      <description>&lt;P&gt;Sure. I would use &lt;CODE&gt;eval&lt;/CODE&gt; for this. The process would be to first extract the field containing the IP address, then use &lt;CODE&gt;eval&lt;/CODE&gt; for determining whether the IP address is internal or external and write the result to a field, and finally feed this into timechart.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "src=(?&amp;lt;src_ip&amp;gt;\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" | eval conntype=if(match(src_ip,"^192"),"Outbound","Inbound") | timechart span=1d count by conntype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You could also build this into timechart directly:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "src=(?&amp;lt;src_ip&amp;gt;\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})" | timechart span=1d count(eval(match(src_ip,"^192"))) AS Outbound, count(eval(match(src_ip,"^19[^2]"))) AS Inbound
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;NOTE: I didn't cover the case of purely internal traffic, but that's just a matter of extracting both the source and destination IP and adding the case where they both are considered to be internal. Also NOTE that you shouldn't just be testing whether the address begins with 192, lots of public Internet addresses begin with 192 as well. You should be checking for 192.168.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 13:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56185#M13731</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-01-23T13:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: negative regex in search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56186#M13732</link>
      <description>&lt;P&gt;You're right, I'll check for the 192.168.&lt;/P&gt;

&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2012 13:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/negative-regex-in-search-command/m-p/56186#M13732</guid>
      <dc:creator>AdrienW</dc:creator>
      <dc:date>2012-01-23T13:38:49Z</dc:date>
    </item>
  </channel>
</rss>

