<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Use Regex and filter out the GET logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374981#M160468</link>
    <description>&lt;P&gt;This regex string matches your sample data set.  It's hardcoded for the three IP addresses you gave.  If the real address is larger, the regex may become unmanageable.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;GET\s\/\s-\s80\s-\s10\.228\.(?:9\.1|23\.241|23\.242)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 30 Jun 2017 15:32:58 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-06-30T15:32:58Z</dc:date>
    <item>
      <title>How to Use Regex and filter out the GET logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374979#M160466</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;We want to filter the data using REGEX in props.conf and tansforms.conf but still the data is coming into Splunk. We have tried few methods but still logs are reaching splunk so kindly help on this request.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 13:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374979#M160466</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2017-06-30T13:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to Use Regex and filter out the GET logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374980#M160467</link>
      <description>&lt;P&gt;Do this:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;BR /&gt;
If you are doing this, show us your settings.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 15:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374980#M160467</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-30T15:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to Use Regex and filter out the GET logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374981#M160468</link>
      <description>&lt;P&gt;This regex string matches your sample data set.  It's hardcoded for the three IP addresses you gave.  If the real address is larger, the regex may become unmanageable.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;GET\s\/\s-\s80\s-\s10\.228\.(?:9\.1|23\.241|23\.242)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 30 Jun 2017 15:32:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374981#M160468</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-06-30T15:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to Use Regex and filter out the GET logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374982#M160469</link>
      <description>&lt;P&gt;It is in the documentation here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 14:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Use-Regex-and-filter-out-the-GET-logs/m-p/374982#M160469</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-07-03T14:54:26Z</dc:date>
    </item>
  </channel>
</rss>

