<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to match multiple regex in splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566723#M197485</link>
    <description>&lt;P&gt;Without knowing what you are actually trying to capture (some example events would be useful), it is difficult to say how it can be fixed, but in simple terms, a lot of the capture groups have not been closed, so simply adding some closing parentheses will make the regex valid, although it may not give you what you want&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?i)union.*?select.*?from
(?i:\b(?:(?:m(?:s(?:ys(?:ac(?:cess(?:objects|storage|xml)|es)|(?:relationship|object|querie)s|modules2?))))))&lt;/LI-CODE&gt;</description>
    <pubDate>Sat, 11 Sep 2021 16:39:54 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-09-11T16:39:54Z</dc:date>
    <item>
      <title>how to match multiple regex in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566722#M197484</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;I have multiple string that are regex, i want to find logs that match with this string.&lt;BR /&gt;this is a example of my regex:&lt;BR /&gt;(?i)union.*?select.*?from&lt;BR /&gt;(?i:\b(?:(?:m(?:s(?:ys(?:ac(?:cess(?:objects|storage|xml)|es)|(?:relationship|object|querie)s|modules2?)&lt;/P&gt;&lt;P&gt;and when i write&amp;nbsp;&lt;BR /&gt;index="xyz" | regex "(?i)union.*?select.*?from |&amp;nbsp;(?i:\b(?:(?:m(?:s(?:ys(?:ac(?:cess(?:objects|storage|xml)|es)|(?:relationship|object|querie)s|modules2?)"&lt;BR /&gt;didn't show true result.&lt;/P&gt;&lt;P&gt;how can i write it? please help me.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 16:18:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566722#M197484</guid>
      <dc:creator>szone</dc:creator>
      <dc:date>2021-09-11T16:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to match multiple regex in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566723#M197485</link>
      <description>&lt;P&gt;Without knowing what you are actually trying to capture (some example events would be useful), it is difficult to say how it can be fixed, but in simple terms, a lot of the capture groups have not been closed, so simply adding some closing parentheses will make the regex valid, although it may not give you what you want&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?i)union.*?select.*?from
(?i:\b(?:(?:m(?:s(?:ys(?:ac(?:cess(?:objects|storage|xml)|es)|(?:relationship|object|querie)s|modules2?))))))&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 11 Sep 2021 16:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566723#M197485</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-11T16:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: how to match multiple regex in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566727#M197489</link>
      <description>&lt;P&gt;i want to capture strings matched with that regex and the regex is from good source and don't need to&amp;nbsp;&lt;SPAN&gt;closing parentheses and i write part of the entire of string for summarize and example.&lt;BR /&gt;please help me.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 17:11:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566727#M197489</guid>
      <dc:creator>szone</dc:creator>
      <dc:date>2021-09-11T17:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: how to match multiple regex in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566728#M197490</link>
      <description>&lt;P&gt;Rather than using non-capture groups (?:pattern) use capture groups (?&amp;lt;fieldname&amp;gt;pattern)&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 17:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566728#M197490</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-11T17:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: how to match multiple regex in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566729#M197491</link>
      <description>&lt;P&gt;please&amp;nbsp;Explain in more detail. I'm new in splunk.&lt;BR /&gt;two of string is:&lt;BR /&gt;(?i:\b(?:(?:m(?:s(?:ys(?:ac(?:cess(?:objects|storage|xml)|es)|(?:relationship|object|querie)s|modules2?)|db)|aster\.\.sysdatabases|ysql\.db)|pg_(?:catalog|toast)|information_schema|northwind|tempdb)\b|s(?:(?:ys(?:\.database_name|aux)|qlite(?:_temp)?_master)\b|chema(?:_name\b|\W*\())|d(?:atabas|b_nam)e\W*\())&lt;BR /&gt;&amp;nbsp;and&lt;BR /&gt;(?i)union.*?select.*?from&lt;BR /&gt;please help me&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 18:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566729#M197491</guid>
      <dc:creator>szone</dc:creator>
      <dc:date>2021-09-11T18:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: how to match multiple regex in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566800#M197511</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;said, to help you we are needing your sample data and explanation what you try to get from that sample (if it's not obviously based on your sample). Otherwise you could try it with&amp;nbsp;&lt;A href="https://regex101.com" target="_blank"&gt;https://regex101.com&lt;/A&gt;&amp;nbsp;which also have option to save &amp;amp; share your regex.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 08:06:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-match-multiple-regex-in-splunk/m-p/566800#M197511</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-13T08:06:47Z</dc:date>
    </item>
  </channel>
</rss>

