<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex/Rex - Non Capture Groups in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508304#M142034</link>
    <description>&lt;P&gt;Mate that's awesome. Solves my issue and much more.&lt;BR /&gt;&lt;BR /&gt;It never occurred to me once that (?&amp;lt;Name_Of_Field&amp;gt;) could be positioned anywhere within the regex.&lt;/P&gt;&lt;P&gt;I thought it always had to sit at the front of the sequence.&lt;/P&gt;&lt;P&gt;That opens up a whole lot of other options with some other work I have on.&lt;BR /&gt;&lt;BR /&gt;Out of curiosity, are you able to explain how the section "[^,]+" works?&lt;/P&gt;&lt;P&gt;Much appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jul 2020 13:45:59 GMT</pubDate>
    <dc:creator>Curlyshrew</dc:creator>
    <dc:date>2020-07-09T13:45:59Z</dc:date>
    <item>
      <title>Regex/Rex - Non Capture Groups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/507945#M141971</link>
      <description>&lt;P&gt;Hi all. New here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I have been working with some data strings that contain varied asset numbers for computers and servers.&lt;/P&gt;&lt;P&gt;As unfortunately our naming conventions are all over the place for a small number of assets as well as the server asset names being considerably different from endpoint PC's, I have been left with using the following to capture the sequence:&lt;/P&gt;&lt;P&gt;(?:Computer Name:)(.*)(?:,)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -- (Yucky Wildcard)&lt;/P&gt;&lt;P&gt;For Splunk, this would be:&lt;/P&gt;&lt;P&gt;| rex "(?&amp;lt;Computer&amp;gt;(?:Computer Name:)(.*?)(?:,))"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The dilemma is that the non-capture group (?:Computer Name) is being captured in the results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am unsure but I assume it is due to the first capture group "(?&amp;lt;Computer&amp;gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my little experience with playing with rex, I do know that non-capture groups work in-front of a capture group but I have had no success in having them before a capture group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for listening to my TED talk&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 00:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/507945#M141971</guid>
      <dc:creator>Curlyshrew</dc:creator>
      <dc:date>2020-07-08T00:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Regex/Rex - Non Capture Groups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/507949#M141972</link>
      <description>&lt;P&gt;Could you please provide a small dummy-sample of your data to review and. test the regex?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;On a side note, you may want to normalize the naming conventions.&amp;nbsp; &amp;nbsp;This can be done at the source (maybe?), at index time, or at search time (e.g. create a lookup that outputs friendly names for server assets&amp;nbsp; and endpoint PCs, or use the &lt;EM&gt;coalesce&lt;/EM&gt; function of the eval command).&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 01:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/507949#M141972</guid>
      <dc:creator>_gkollias</dc:creator>
      <dc:date>2020-07-08T01:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Regex/Rex - Non Capture Groups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508211#M142020</link>
      <description>&lt;P&gt;Apologies on the delay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's some example raw data that I am working with. Again the computer names change in length, consistency per result&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have marked the fields in bold that I am attempting to extract.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2020-07-04&lt;/SPAN&gt; &lt;SPAN&gt;21:36:33&lt;/SPAN&gt;,&lt;SPAN&gt;Compressed&lt;/SPAN&gt; &lt;SPAN&gt;File&lt;/SPAN&gt;,&lt;SPAN&gt;IP&lt;/SPAN&gt; &lt;SPAN&gt;Address:&lt;/SPAN&gt; &lt;SPAN&gt;192.168.1.1&lt;/SPAN&gt;,&lt;STRONG&gt;Computer name: GHCC01SFG435&lt;/STRONG&gt;,&lt;SPAN&gt;Source:&lt;/SPAN&gt; &lt;SPAN&gt;Scheduled&lt;/SPAN&gt; &lt;SPAN&gt;scan&lt;/SPAN&gt;,&lt;SPAN&gt;Risk&lt;/SPAN&gt; &lt;SPAN&gt;name:&lt;/SPAN&gt; &lt;SPAN&gt;Heur.AdvML.B&lt;/SPAN&gt;,&lt;SPAN&gt;Occurrences:&lt;/SPAN&gt; &lt;SPAN&gt;1&lt;/SPAN&gt;,&lt;SPAN&gt;File&lt;/SPAN&gt; &lt;SPAN&gt;path:&lt;/SPAN&gt; &lt;SPAN&gt;T:\Tower\Installer\fgg5cfef.msi&lt;/SPAN&gt;,&lt;SPAN&gt;Description:&lt;/SPAN&gt; &lt;SPAN&gt;Still&lt;/SPAN&gt; &lt;SPAN&gt;contains&lt;/SPAN&gt; &lt;SPAN&gt;1&lt;/SPAN&gt; &lt;SPAN&gt;infected&lt;/SPAN&gt; &lt;SPAN&gt;items&lt;/SPAN&gt;,&lt;SPAN&gt;Actual&lt;/SPAN&gt; &lt;SPAN&gt;action:&lt;/SPAN&gt; &lt;SPAN&gt;Quarantined&lt;/SPAN&gt;,&lt;SPAN&gt;Requested&lt;/SPAN&gt; &lt;SPAN&gt;action:&lt;/SPAN&gt; &lt;SPAN&gt;Quarantined&lt;/SPAN&gt;,&lt;SPAN&gt;Secondary&lt;/SPAN&gt; &lt;SPAN&gt;action:&lt;/SPAN&gt; &lt;SPAN&gt;Left&lt;/SPAN&gt; &lt;SPAN&gt;alone&lt;/SPAN&gt;,&lt;SPAN&gt;Event&lt;/SPAN&gt; &lt;SPAN&gt;time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-04&lt;/SPAN&gt; &lt;SPAN&gt;21:33:58&lt;/SPAN&gt;,&lt;SPAN&gt;Event&lt;/SPAN&gt; &lt;SPAN&gt;Insert&lt;/SPAN&gt; &lt;SPAN&gt;Time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-04&lt;/SPAN&gt; &lt;SPAN&gt;21:36:33&lt;/SPAN&gt;,&lt;SPAN&gt;End&lt;/SPAN&gt; &lt;SPAN&gt;Time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-04&lt;/SPAN&gt; &lt;SPAN&gt;21:33:58&lt;/SPAN&gt;,&lt;SPAN&gt;Last&lt;/SPAN&gt; &lt;SPAN&gt;update&lt;/SPAN&gt; &lt;SPAN&gt;time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-04&lt;/SPAN&gt; &lt;SPAN&gt;21:36:33&lt;/SPAN&gt;,&lt;SPAN&gt;Domain&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;Default&lt;/SPAN&gt;,&lt;SPAN&gt;Group&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;My&lt;/SPAN&gt; &lt;SPAN&gt;Company\HODW&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;Server\HODW&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;Development&lt;/SPAN&gt;,&lt;SPAN&gt;Server&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;FGTY1ADA02&lt;/SPAN&gt;,&lt;SPAN&gt;User&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;SYSTEM&lt;/SPAN&gt;,&lt;SPAN&gt;Source&lt;/SPAN&gt; &lt;SPAN&gt;Computer&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; ,&lt;SPAN&gt;Source&lt;/SPAN&gt; &lt;SPAN&gt;Computer&lt;/SPAN&gt; &lt;SPAN&gt;IP:&lt;/SPAN&gt; ,&lt;SPAN&gt;Disposition:&lt;/SPAN&gt; &lt;SPAN&gt;Good&lt;/SPAN&gt;,&lt;SPAN&gt;Download&lt;/SPAN&gt; &lt;SPAN&gt;site:&lt;/SPAN&gt; &lt;SPAN&gt;null&lt;/SPAN&gt;,&lt;SPAN&gt;Web&lt;/SPAN&gt; &lt;SPAN&gt;domain:&lt;/SPAN&gt; &lt;SPAN&gt;null&lt;/SPAN&gt;,&lt;SPAN&gt;Downloaded&lt;/SPAN&gt; &lt;SPAN&gt;by:&lt;/SPAN&gt; &lt;SPAN&gt;null&lt;/SPAN&gt;,&lt;SPAN&gt;Prevalence:&lt;/SPAN&gt; &lt;SPAN&gt;Reputation&lt;/SPAN&gt; &lt;SPAN&gt;was&lt;/SPAN&gt; &lt;SPAN&gt;not&lt;/SPAN&gt; &lt;SPAN&gt;used&lt;/SPAN&gt; &lt;SPAN&gt;in&lt;/SPAN&gt; &lt;SPAN&gt;this&lt;/SPAN&gt; &lt;SPAN&gt;detection.&lt;/SPAN&gt;,&lt;SPAN&gt;Confidence:&lt;/SPAN&gt; &lt;SPAN&gt;Reputation&lt;/SPAN&gt; &lt;SPAN&gt;was&lt;/SPAN&gt; &lt;SPAN&gt;not&lt;/SPAN&gt; &lt;SPAN&gt;used&lt;/SPAN&gt; &lt;SPAN&gt;in&lt;/SPAN&gt; &lt;SPAN&gt;this&lt;/SPAN&gt; &lt;SPAN&gt;detection.&lt;/SPAN&gt;,&lt;SPAN&gt;URL&lt;/SPAN&gt; &lt;SPAN&gt;Tracking&lt;/SPAN&gt; &lt;SPAN&gt;Status:&lt;/SPAN&gt; &lt;SPAN&gt;Off&lt;/SPAN&gt;,&lt;SPAN&gt;First&lt;/SPAN&gt; &lt;SPAN&gt;Seen:&lt;/SPAN&gt; &lt;SPAN&gt;Reputation&lt;/SPAN&gt; &lt;SPAN&gt;was&lt;/SPAN&gt; &lt;SPAN&gt;not&lt;/SPAN&gt; &lt;SPAN&gt;used&lt;/SPAN&gt; &lt;SPAN&gt;in&lt;/SPAN&gt; &lt;SPAN&gt;this&lt;/SPAN&gt; &lt;SPAN&gt;detection.&lt;/SPAN&gt;,&lt;SPAN&gt;Sensitivity:&lt;/SPAN&gt; &lt;SPAN&gt;Low&lt;/SPAN&gt;,&lt;SPAN&gt;Permitted&lt;/SPAN&gt; &lt;SPAN&gt;application&lt;/SPAN&gt; &lt;SPAN&gt;reason:&lt;/SPAN&gt; &lt;SPAN&gt;Not&lt;/SPAN&gt; &lt;SPAN&gt;on&lt;/SPAN&gt; &lt;SPAN&gt;the&lt;/SPAN&gt; &lt;SPAN&gt;permitted&lt;/SPAN&gt; &lt;SPAN&gt;application&lt;/SPAN&gt; &lt;SPAN&gt;list&lt;/SPAN&gt;,&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;hash:&lt;/SPAN&gt; ,&lt;SPAN&gt;Hash&lt;/SPAN&gt; &lt;SPAN&gt;type:&lt;/SPAN&gt; &lt;SPAN&gt;SHA1&lt;/SPAN&gt;,&lt;SPAN&gt;Company&lt;/SPAN&gt; &lt;SPAN&gt;name:&lt;/SPAN&gt; ,&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;name:&lt;/SPAN&gt; ,&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;version:&lt;/SPAN&gt; ,&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;type:&lt;/SPAN&gt; &lt;SPAN&gt;-1&lt;/SPAN&gt;,&lt;SPAN&gt;File&lt;/SPAN&gt; &lt;SPAN&gt;size&lt;/SPAN&gt; (&lt;SPAN&gt;bytes&lt;/SPAN&gt;)&lt;SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN&gt;0&lt;/SPAN&gt;,&lt;SPAN&gt;Category&lt;/SPAN&gt; &lt;SPAN&gt;set:&lt;/SPAN&gt; &lt;SPAN&gt;Malware&lt;/SPAN&gt;,&lt;SPAN&gt;Category&lt;/SPAN&gt; &lt;SPAN&gt;type:&lt;/SPAN&gt; &lt;SPAN&gt;Heuristic&lt;/SPAN&gt; &lt;SPAN&gt;Virus&lt;/SPAN&gt;,&lt;SPAN&gt;Location:&lt;/SPAN&gt; &lt;SPAN&gt;Default&lt;/SPAN&gt;,&lt;SPAN&gt;Intensive&lt;/SPAN&gt; &lt;SPAN&gt;Protection&lt;/SPAN&gt; &lt;SPAN&gt;Level:&lt;/SPAN&gt; &lt;SPAN&gt;0&lt;/SPAN&gt;,&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;issuer:&lt;/SPAN&gt; ,&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;signer:&lt;/SPAN&gt; ,&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;thumbprint:&lt;/SPAN&gt; ,&lt;SPAN&gt;Signing&lt;/SPAN&gt; &lt;SPAN&gt;timestamp:&lt;/SPAN&gt; ,&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;serial&lt;/SPAN&gt; &lt;SPAN&gt;number:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2020-07-08&lt;/SPAN&gt; &lt;SPAN&gt;11:59:34&lt;/SPAN&gt;,&lt;SPAN&gt;Virus&lt;/SPAN&gt; &lt;SPAN&gt;found&lt;/SPAN&gt;,&lt;SPAN&gt;IP&lt;/SPAN&gt; &lt;SPAN&gt;Address:&lt;/SPAN&gt; &lt;SPAN&gt;172.16.10.151&lt;/SPAN&gt;,&lt;STRONG&gt;Computer name: U1135713&lt;/STRONG&gt;,&lt;SPAN&gt;Source:&lt;/SPAN&gt; &lt;SPAN&gt;Auto-Protect&lt;/SPAN&gt; &lt;SPAN&gt;scan&lt;/SPAN&gt;,&lt;SPAN&gt;Risk&lt;/SPAN&gt; &lt;SPAN&gt;name:&lt;/SPAN&gt; &lt;SPAN&gt;Heur.AdvML.C&lt;/SPAN&gt;,&lt;SPAN&gt;Occurrences:&lt;/SPAN&gt; &lt;SPAN&gt;1&lt;/SPAN&gt;,&lt;SPAN&gt;File&lt;/SPAN&gt; &lt;SPAN&gt;path:&lt;/SPAN&gt; &lt;SPAN&gt;C:\Windows\DVV\v4.0.6\namespace\hodw.tergtaw.fnd\user\user0\IUWGR\personal&lt;/SPAN&gt; &lt;SPAN&gt;work\maliciousfile.exe&lt;/SPAN&gt;,&lt;SPAN&gt;Description:&lt;/SPAN&gt; ,&lt;SPAN&gt;Actual&lt;/SPAN&gt; &lt;SPAN&gt;action:&lt;/SPAN&gt; &lt;SPAN&gt;Deleted&lt;/SPAN&gt;,&lt;SPAN&gt;Requested&lt;/SPAN&gt; &lt;SPAN&gt;action:&lt;/SPAN&gt; &lt;SPAN&gt;Cleaned&lt;/SPAN&gt;,&lt;SPAN&gt;Secondary&lt;/SPAN&gt; &lt;SPAN&gt;action:&lt;/SPAN&gt; &lt;SPAN&gt;Deleted&lt;/SPAN&gt;,&lt;SPAN&gt;Event&lt;/SPAN&gt; &lt;SPAN&gt;time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-08&lt;/SPAN&gt; &lt;SPAN&gt;11:55:57&lt;/SPAN&gt;,&lt;SPAN&gt;Event&lt;/SPAN&gt; &lt;SPAN&gt;Insert&lt;/SPAN&gt; &lt;SPAN&gt;Time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-08&lt;/SPAN&gt; &lt;SPAN&gt;11:59:34&lt;/SPAN&gt;,&lt;SPAN&gt;End&lt;/SPAN&gt; &lt;SPAN&gt;Time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-08&lt;/SPAN&gt; &lt;SPAN&gt;11:55:57&lt;/SPAN&gt;,&lt;SPAN&gt;Last&lt;/SPAN&gt; &lt;SPAN&gt;update&lt;/SPAN&gt; &lt;SPAN&gt;time:&lt;/SPAN&gt; &lt;SPAN&gt;2020-07-08&lt;/SPAN&gt; &lt;SPAN&gt;11:59:34&lt;/SPAN&gt;,&lt;SPAN&gt;Domain&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;Default&lt;/SPAN&gt;,&lt;SPAN&gt;Group&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;My&lt;/SPAN&gt; &lt;SPAN&gt;Company\HODW&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;Server\HODW&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;HODW\HODW&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;Windows&lt;/SPAN&gt; &lt;SPAN&gt;10\HODW&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;BHTPN&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;Online&lt;/SPAN&gt; &lt;SPAN&gt;Default&lt;/SPAN&gt;,&lt;SPAN&gt;Server&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;FGTY1ADA02&lt;/SPAN&gt;,&lt;SPAN&gt;User&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;IUWGR&lt;/SPAN&gt;,&lt;SPAN&gt;Source&lt;/SPAN&gt; &lt;SPAN&gt;Computer&lt;/SPAN&gt; &lt;SPAN&gt;Name:&lt;/SPAN&gt; &lt;SPAN&gt;U1135713. hodw.tergtaw.fnd&lt;/SPAN&gt;,&lt;SPAN&gt;Source&lt;/SPAN&gt; &lt;SPAN&gt;Computer&lt;/SPAN&gt; &lt;SPAN&gt;IP:&lt;/SPAN&gt; &lt;SPAN&gt;127.0.0.1&lt;/SPAN&gt;,&lt;SPAN&gt;Disposition:&lt;/SPAN&gt; &lt;SPAN&gt;Bad&lt;/SPAN&gt;,&lt;SPAN&gt;Download&lt;/SPAN&gt; &lt;SPAN&gt;site:&lt;/SPAN&gt; ,&lt;SPAN&gt;Web&lt;/SPAN&gt; &lt;SPAN&gt;domain:&lt;/SPAN&gt; ,&lt;SPAN&gt;Downloaded&lt;/SPAN&gt; &lt;SPAN&gt;by:&lt;/SPAN&gt; &lt;SPAN&gt;svchost.exe&lt;/SPAN&gt;,&lt;SPAN&gt;Prevalence:&lt;/SPAN&gt; &lt;SPAN&gt;This&lt;/SPAN&gt; &lt;SPAN&gt;file&lt;/SPAN&gt; &lt;SPAN&gt;has&lt;/SPAN&gt; &lt;SPAN&gt;been&lt;/SPAN&gt; &lt;SPAN&gt;seen&lt;/SPAN&gt; &lt;SPAN&gt;by&lt;/SPAN&gt; &lt;SPAN&gt;hundreds&lt;/SPAN&gt; &lt;SPAN&gt;of&lt;/SPAN&gt; &lt;SPAN&gt;Symantec&lt;/SPAN&gt; &lt;SPAN&gt;users.&lt;/SPAN&gt;,&lt;SPAN&gt;Confidence:&lt;/SPAN&gt; &lt;SPAN&gt;This&lt;/SPAN&gt; &lt;SPAN&gt;file&lt;/SPAN&gt; &lt;SPAN&gt;is&lt;/SPAN&gt; &lt;SPAN&gt;untrustworthy.&lt;/SPAN&gt;,&lt;SPAN&gt;URL&lt;/SPAN&gt; &lt;SPAN&gt;Tracking&lt;/SPAN&gt; &lt;SPAN&gt;Status:&lt;/SPAN&gt; &lt;SPAN&gt;On&lt;/SPAN&gt;,&lt;SPAN&gt;First&lt;/SPAN&gt; &lt;SPAN&gt;Seen:&lt;/SPAN&gt; &lt;SPAN&gt;Symantec&lt;/SPAN&gt; &lt;SPAN&gt;has&lt;/SPAN&gt; &lt;SPAN&gt;known&lt;/SPAN&gt; &lt;SPAN&gt;about&lt;/SPAN&gt; &lt;SPAN&gt;this&lt;/SPAN&gt; &lt;SPAN&gt;file&lt;/SPAN&gt; &lt;SPAN&gt;for&lt;/SPAN&gt; &lt;SPAN&gt;more&lt;/SPAN&gt; &lt;SPAN&gt;than&lt;/SPAN&gt; &lt;SPAN&gt;1&lt;/SPAN&gt; &lt;SPAN&gt;year.&lt;/SPAN&gt;,&lt;SPAN&gt;Sensitivity:&lt;/SPAN&gt; ,&lt;SPAN&gt;Permitted&lt;/SPAN&gt; &lt;SPAN&gt;application&lt;/SPAN&gt; &lt;SPAN&gt;reason:&lt;/SPAN&gt; &lt;SPAN&gt;Not&lt;/SPAN&gt; &lt;SPAN&gt;on&lt;/SPAN&gt; &lt;SPAN&gt;the&lt;/SPAN&gt; &lt;SPAN&gt;permitted&lt;/SPAN&gt; &lt;SPAN&gt;application&lt;/SPAN&gt; &lt;SPAN&gt;list&lt;/SPAN&gt;,&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;hash:&lt;/SPAN&gt; &lt;SPAN&gt;500D8BB5500663G76016C16C377518E700287332406A5FAF3FDC8E87FBF51273&lt;/SPAN&gt;,&lt;SPAN&gt;Hash&lt;/SPAN&gt; &lt;SPAN&gt;type:&lt;/SPAN&gt; &lt;SPAN&gt;SHA2&lt;/SPAN&gt;,"&lt;SPAN&gt;Company&lt;/SPAN&gt; &lt;SPAN&gt;name:&lt;/SPAN&gt; &lt;SPAN&gt;W3i&lt;/SPAN&gt;, &lt;SPAN&gt;LLC&lt;/SPAN&gt;",&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;name:&lt;/SPAN&gt; &lt;SPAN&gt;Brueze.com&lt;/SPAN&gt; &lt;SPAN&gt;Installation&lt;/SPAN&gt; &lt;SPAN&gt;Utility&lt;/SPAN&gt;,&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;version:&lt;/SPAN&gt; &lt;SPAN&gt;1&lt;/SPAN&gt;, &lt;SPAN&gt;0&lt;/SPAN&gt;, &lt;SPAN&gt;36&lt;/SPAN&gt;, &lt;SPAN&gt;0&lt;/SPAN&gt;,&lt;SPAN&gt;Application&lt;/SPAN&gt; &lt;SPAN&gt;type:&lt;/SPAN&gt; &lt;SPAN&gt;127&lt;/SPAN&gt;,&lt;SPAN&gt;File&lt;/SPAN&gt; &lt;SPAN&gt;size&lt;/SPAN&gt; (&lt;SPAN&gt;bytes&lt;/SPAN&gt;)&lt;SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN&gt;12680312&lt;/SPAN&gt;,&lt;SPAN&gt;Category&lt;/SPAN&gt; &lt;SPAN&gt;set:&lt;/SPAN&gt; &lt;SPAN&gt;Malware&lt;/SPAN&gt;,&lt;SPAN&gt;Category&lt;/SPAN&gt; &lt;SPAN&gt;type:&lt;/SPAN&gt; &lt;SPAN&gt;Heuristic&lt;/SPAN&gt; &lt;SPAN&gt;Virus&lt;/SPAN&gt;,&lt;SPAN&gt;Location:&lt;/SPAN&gt; &lt;SPAN&gt;BHTPN&lt;/SPAN&gt; &lt;SPAN&gt;-&lt;/SPAN&gt; &lt;SPAN&gt;TPN&lt;/SPAN&gt; &lt;SPAN&gt;Connected&lt;/SPAN&gt; (&lt;SPAN&gt;Wireless-Mobile&lt;/SPAN&gt;),&lt;SPAN&gt;Intensive&lt;/SPAN&gt; &lt;SPAN&gt;Protection&lt;/SPAN&gt; &lt;SPAN&gt;Level:&lt;/SPAN&gt; &lt;SPAN&gt;0&lt;/SPAN&gt;,"&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;issuer:&lt;/SPAN&gt; &lt;SPAN&gt;W3i&lt;/SPAN&gt;,&lt;SPAN&gt;LLC&lt;/SPAN&gt;",&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;signer:&lt;/SPAN&gt; &lt;SPAN&gt;VeriSign&lt;/SPAN&gt; &lt;SPAN&gt;Class&lt;/SPAN&gt; &lt;SPAN&gt;3&lt;/SPAN&gt; &lt;SPAN&gt;Code&lt;/SPAN&gt; &lt;SPAN&gt;Signing&lt;/SPAN&gt; &lt;SPAN&gt;2004&lt;/SPAN&gt; &lt;SPAN&gt;CA&lt;/SPAN&gt;,&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;thumbprint:&lt;/SPAN&gt; &lt;SPAN&gt;C1102EA03313E71D4E3C771A823E152375CDEF4E&lt;/SPAN&gt;,&lt;SPAN&gt;Signing&lt;/SPAN&gt; &lt;SPAN&gt;timestamp:&lt;/SPAN&gt; &lt;SPAN&gt;0&lt;/SPAN&gt;,&lt;SPAN&gt;Certificate&lt;/SPAN&gt; &lt;SPAN&gt;serial&lt;/SPAN&gt; &lt;SPAN&gt;number:&lt;/SPAN&gt; &lt;SPAN&gt;391B1DE3FDF7D68124136D1483C16B21&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 00:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508211#M142020</guid>
      <dc:creator>Curlyshrew</dc:creator>
      <dc:date>2020-07-09T00:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Regex/Rex - Non Capture Groups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508243#M142023</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223446"&gt;@Curlyshrew&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Please, try this regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;! rex "Computer\s+name:\s+(?&amp;lt;Computer_Name&amp;gt;[^,]+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/pJSLDQ/1" target="_blank"&gt;https://regex101.com/r/pJSLDQ/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 07:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508243#M142023</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-09T07:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Regex/Rex - Non Capture Groups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508304#M142034</link>
      <description>&lt;P&gt;Mate that's awesome. Solves my issue and much more.&lt;BR /&gt;&lt;BR /&gt;It never occurred to me once that (?&amp;lt;Name_Of_Field&amp;gt;) could be positioned anywhere within the regex.&lt;/P&gt;&lt;P&gt;I thought it always had to sit at the front of the sequence.&lt;/P&gt;&lt;P&gt;That opens up a whole lot of other options with some other work I have on.&lt;BR /&gt;&lt;BR /&gt;Out of curiosity, are you able to explain how the section "[^,]+" works?&lt;/P&gt;&lt;P&gt;Much appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 13:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508304#M142034</guid>
      <dc:creator>Curlyshrew</dc:creator>
      <dc:date>2020-07-09T13:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Regex/Rex - Non Capture Groups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508322#M142035</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223446"&gt;@Curlyshrew&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in regex101 is described every part of the regex capture (on the right side).&lt;/P&gt;&lt;P&gt;Anyway, [^,]* means that you take all the characters (also spaces) until ",".&lt;/P&gt;&lt;P&gt;It's a very useful way to manage regex capture groups!&lt;/P&gt;&lt;P&gt;Only one point of attention: remember always to escape special chars, in other words, if instead of "," you have to take all the chars until "?", you should use [^\?]*.&lt;/P&gt;&lt;P&gt;Ciao and next time!&lt;/P&gt;&lt;P&gt;Giuseppe&lt;BR /&gt;P.S.: Karma Points are valued &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 14:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-Rex-Non-Capture-Groups/m-p/508322#M142035</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-09T14:44:12Z</dc:date>
    </item>
  </channel>
</rss>

