<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need a regex improvement in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568997#M198319</link>
    <description>&lt;P&gt;Well. The typical regex used often to capture IP addresses is \d{1,3}\.\d{1,3}\.\d{1,3}\d{1,3}&lt;/P&gt;&lt;P&gt;Unfortunately, it doesn't validate the validity of the captured addres and accepts values over 255. It can be improved but it quickly gets ugly&lt;/P&gt;&lt;P&gt;((1?\d{1,2})|2([0-4]\d|5[0-5]))\d((1?\d{1,2})|2([0-4]\d|5[0-5]))\d((1?\d{1,2})|2([0-4]\d|5[0-5]))\d((1?\d{1,2})|2([0-4]\d|5[0-5]))&lt;/P&gt;&lt;P&gt;Something like that - I'm writing it on the fly so can't guarantee correctness &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Regex is not very well suited for matching IP's&lt;/P&gt;&lt;P&gt;Anyway, if you want to capture just the four octet sequence with a guarantee that it's not preceedee or continued by any dot-delimited sequence, you might want to match (^|[^.]) at the beginning and ($|[^.]) at the end (you don't escape the dot in character set)&lt;/P&gt;&lt;P&gt;So effectively (in the simple - non-validating form) you end up with&lt;/P&gt;&lt;PRE&gt;(^|[^.])(?&amp;lt;IP&amp;gt;\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})($|[^.])&lt;/PRE&gt;</description>
    <pubDate>Wed, 29 Sep 2021 18:45:19 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-09-29T18:45:19Z</dc:date>
    <item>
      <title>Need a regex improvement</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568987#M198314</link>
      <description>&lt;P&gt;| rex field=_raw "(?&amp;lt;dscvIP&amp;gt;[^\.]\d+\.\d+\.\d+\.\d+[\s|\:])"&lt;/P&gt;&lt;P&gt;Using the above rex command to try to capture IP addresses, an it works most of the time, but I still get a few false positives for ESX log entries that contain the following&lt;/P&gt;&lt;P&gt;Rcv-tx-10.20.30.45.78.80&lt;/P&gt;&lt;P&gt;The rex field captures 30.45.78.80 as the dscvIP field. I thought by adding the [^\.] to the beginning of the regex match it would not capture an string matching the IP syntax that had a period(.) immediately preceding the string. And I also thought this string would be skipped all together because for it to not start with a period(.) , the match would have to go to the dash(-) following tx, but then would not match because there is not a space or colon after the 4th \d+ match.&lt;/P&gt;&lt;P&gt;What am&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:21:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568987#M198314</guid>
      <dc:creator>tinylund</dc:creator>
      <dc:date>2021-09-29T18:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex improvement</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568991#M198316</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183121"&gt;@tinylund&lt;/a&gt;&amp;nbsp;Can you share the raw event ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568991#M198316</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-29T18:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex improvement</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568996#M198318</link>
      <description>&lt;P&gt;date FQN date:time FQN vmkernel: cpu16:66435)CpuSched: 694: user latency of 418901 RPC-tx-10.20.30.45.78.80 0 changed by 66435 NFSv3-RemountHandler -6&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568996#M198318</guid>
      <dc:creator>tinylund</dc:creator>
      <dc:date>2021-09-29T18:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex improvement</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568997#M198319</link>
      <description>&lt;P&gt;Well. The typical regex used often to capture IP addresses is \d{1,3}\.\d{1,3}\.\d{1,3}\d{1,3}&lt;/P&gt;&lt;P&gt;Unfortunately, it doesn't validate the validity of the captured addres and accepts values over 255. It can be improved but it quickly gets ugly&lt;/P&gt;&lt;P&gt;((1?\d{1,2})|2([0-4]\d|5[0-5]))\d((1?\d{1,2})|2([0-4]\d|5[0-5]))\d((1?\d{1,2})|2([0-4]\d|5[0-5]))\d((1?\d{1,2})|2([0-4]\d|5[0-5]))&lt;/P&gt;&lt;P&gt;Something like that - I'm writing it on the fly so can't guarantee correctness &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Regex is not very well suited for matching IP's&lt;/P&gt;&lt;P&gt;Anyway, if you want to capture just the four octet sequence with a guarantee that it's not preceedee or continued by any dot-delimited sequence, you might want to match (^|[^.]) at the beginning and ($|[^.]) at the end (you don't escape the dot in character set)&lt;/P&gt;&lt;P&gt;So effectively (in the simple - non-validating form) you end up with&lt;/P&gt;&lt;PRE&gt;(^|[^.])(?&amp;lt;IP&amp;gt;\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})($|[^.])&lt;/PRE&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:45:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568997#M198319</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-29T18:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex improvement</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568998#M198320</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183121"&gt;@tinylund&lt;/a&gt;&amp;nbsp;Please try using the below rex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "RPC-tx-(?P&amp;lt;dscvIP&amp;gt;.*?)\s"&lt;/LI-CODE&gt;&lt;P&gt;Also, If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:46:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/568998#M198320</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-29T18:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex improvement</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/569000#M198321</link>
      <description>&lt;P&gt;This is just the raw log that fails, the above rex finds the correct combination in other logs, so I don't want to single out the RPC-tx- (this solution doesn't resolve the issue)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:55:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-a-regex-improvement/m-p/569000#M198321</guid>
      <dc:creator>tinylund</dc:creator>
      <dc:date>2021-09-29T18:55:05Z</dc:date>
    </item>
  </channel>
</rss>

