<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Query Regular Expression in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Regular-Expression/m-p/549092#M155769</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233766"&gt;@ramzadabala&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if in your logs you haven't backslashes before ", your regex is correct.&lt;/P&gt;&lt;P&gt;if instead in your logs you have backslashes before " (as in the sample you shared), the regex isn't correct and you have to modify it in this way:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "consumer_application\\\":\\\"(?P&amp;lt;Consumer&amp;gt;.*?)\\\""&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;You can test the regex at&amp;nbsp;&lt;A href="https://regex101.com/r/us0W8H/1" target="_blank"&gt;https://regex101.com/r/us0W8H/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 23 Apr 2021 09:41:09 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-04-23T09:41:09Z</dc:date>
    <item>
      <title>Splunk Query Regular Expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Regular-Expression/m-p/549087#M155767</link>
      <description>&lt;DIV&gt;&lt;DIV class="grid fd-column fw-nowrap"&gt;&lt;DIV class="grid fw-nowrap"&gt;&lt;DIV class="grid--cell wmn0 fl1 lh-lg"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="grid fw-nowrap fc-black-600"&gt;&lt;DIV class="grid--cell mr8"&gt;Dear Team,&lt;/DIV&gt;&lt;DIV class="grid--cell lh-md"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="mt24 grid gsx gs8"&gt;&lt;SPAN&gt;I've below Splunk log and trying to get stats count based on consumer_application. I've tried below regular expression but no results were returned -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="mt24 grid gsx gs8"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;Splunk Query&lt;/STRONG&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"uri":* (PaymentVerticle) | rex field=_raw "consumer_application\"\:\"(?P&amp;lt;Consumer&amp;gt;.*?)\"" | stats count by Consumer&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Splunk Log&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;2021-04-22T11:31:25.115912284Z app_name=java message={"name":"PaymentVerticle", "timestamp":"2021-04-22T11:31:25.115Z","level":"info","schemaVersion":"0.1","application":{"name":"PaymentVerticle","version":"1.1.1"},"request":{"address":{"uri":"PaymentVerticle"},"metadata":{"correlation_id":"042320210010GMT"}},"message":"Received request with body {\"payment_request\":{\"consumer_application\":\"BLUEPRISM\"}}"}&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 09:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Regular-Expression/m-p/549087#M155767</guid>
      <dc:creator>ramzadabala</dc:creator>
      <dc:date>2021-04-23T09:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query Regular Expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Regular-Expression/m-p/549092#M155769</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233766"&gt;@ramzadabala&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if in your logs you haven't backslashes before ", your regex is correct.&lt;/P&gt;&lt;P&gt;if instead in your logs you have backslashes before " (as in the sample you shared), the regex isn't correct and you have to modify it in this way:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "consumer_application\\\":\\\"(?P&amp;lt;Consumer&amp;gt;.*?)\\\""&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;You can test the regex at&amp;nbsp;&lt;A href="https://regex101.com/r/us0W8H/1" target="_blank"&gt;https://regex101.com/r/us0W8H/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 09:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Regular-Expression/m-p/549092#M155769</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-23T09:41:09Z</dc:date>
    </item>
  </channel>
</rss>

