<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex help required in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549796#M156036</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, I could help you more, if you share some sample of your data (the events not the rule!): data to take and data to exclude.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2021 09:51:37 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-04-29T09:51:37Z</dc:date>
    <item>
      <title>Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549770#M156019</link>
      <description>&lt;DIV&gt;Hi Team,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Can someone provide me the Regex for the below:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;|search (UPN=*T@mail.eeir)&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549770#M156019</guid>
      <dc:creator>SabariRajanT</dc:creator>
      <dc:date>2021-04-29T08:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549773#M156021</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you could share a sample it's easier to help you!&lt;/P&gt;&lt;P&gt;Anyway, what do you need:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;a regex to search all the events where there's the string "&lt;SPAN&gt;UPN=*T@mail.eeir",&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;the extraction of the UPN field?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;If the first you can use:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| regex "UPN\=.*T\@mail\.eeir"&lt;/LI-CODE&gt;&lt;P&gt;If the second, I need a sample.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549773#M156021</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T08:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549783#M156025</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your response. The main gole is to ignore the Capital "T" as shown below in the UPN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;|search (UPN=*T@mail.weir).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you could provide the Query accordingly as per regex 101 that would be great.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sabari&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549783#M156025</guid>
      <dc:creator>SabariRajanT</dc:creator>
      <dc:date>2021-04-29T08:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549784#M156026</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could share a sample?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549784#M156026</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T08:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549785#M156027</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:40:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549785#M156027</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T08:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549787#M156029</link>
      <description>&lt;P&gt;sample - UPN=*t@cloud.weir&lt;/P&gt;&lt;P&gt;Required to remove above "t" and "T".&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 09:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549787#M156029</guid>
      <dc:creator>SabariRajanT</dc:creator>
      <dc:date>2021-04-29T09:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549788#M156030</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please, try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| regex "UPN\=.*(T|t)\@mail\.eeir"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 09:14:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549788#M156030</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T09:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549790#M156032</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.!&lt;/P&gt;&lt;P&gt;It doesn't work out well&lt;/P&gt;&lt;P&gt;When i use a Not operator like below. The "t" "T" should ignore&lt;/P&gt;&lt;P&gt;search NOT (UPN=*t@cloud.eeir)&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 09:33:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549790#M156032</guid>
      <dc:creator>SabariRajanT</dc:creator>
      <dc:date>2021-04-29T09:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549793#M156034</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you tried the search without using regex?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search NOT (UPN=*t@cloud.eeir)&lt;/LI-CODE&gt;&lt;P&gt;Splunk searches aren't case sensitive.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 09:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549793#M156034</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T09:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549794#M156035</link>
      <description>&lt;P class="lia-align-justify"&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Yes did that.! But no luck. There are n no of id's with "T" "t". The regex part will help it out as i believe.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 09:46:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549794#M156035</guid>
      <dc:creator>SabariRajanT</dc:creator>
      <dc:date>2021-04-29T09:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549796#M156036</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, I could help you more, if you share some sample of your data (the events not the rule!): data to take and data to exclude.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 09:51:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549796#M156036</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T09:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549823#M156042</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me explain you the scenario in details:&lt;/P&gt;&lt;P&gt;when I query below, I get the UPN details with "T" as below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=xxx | eval UPN=mvindex('userStates{}.userPrincipalName',0) |search UPN = "*T@mail.eeir"&lt;BR /&gt;|table UPN&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;xxx.mmm@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;yyy.Mmmm@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;zzz.rrrr@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;cccc.eeee&lt;STRONG&gt;T&lt;/STRONG&gt;@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see above data xxx , yyy, cccT UPN data's&amp;nbsp; coming up. But I need to ignore &lt;STRONG&gt;"T" &lt;/STRONG&gt;here and show the rest all UPN data like as below&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;xxx.mmm@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;yyy.Mmmm@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;zzz.rrrr@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;cccc.eeee@mail.eeir&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the same am trying to use below query with regex command. But no luck regex is not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=graphsecurityalert | eval UPN=mvindex('userStates{}.userPrincipalName',0) &lt;STRONG&gt;|rex!=UPN = "*T@mail.eeir" |&lt;/STRONG&gt;table UPN&lt;/P&gt;&lt;P&gt;if you provide the following rex will be great -&lt;STRONG&gt; |rex!=UPN = "*T@mail.eeir" &lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 11:24:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549823#M156042</guid>
      <dc:creator>SabariRajanT</dc:creator>
      <dc:date>2021-04-29T11:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549868#M156054</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224126"&gt;@SabariRajanT&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please, try this regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex mode=sed field=UPN "s/(\w+\.\w+)T|t\@(.*)/\1\@\2/g"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 15:12:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/549868#M156054</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T15:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Regex help required</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/552790#M156911</link>
      <description>&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 14:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-help-required/m-p/552790#M156911</guid>
      <dc:creator>SabariRajanT</dc:creator>
      <dc:date>2021-05-24T14:29:23Z</dc:date>
    </item>
  </channel>
</rss>

