<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Optimize Regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Optimize-Regex/m-p/679324#M232224</link>
    <description>&lt;P&gt;Good to know, thanks, works perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 17:25:25 GMT</pubDate>
    <dc:creator>secphilomath1</dc:creator>
    <dc:date>2024-03-01T17:25:25Z</dc:date>
    <item>
      <title>Optimize Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Optimize-Regex/m-p/679222#M232194</link>
      <description>&lt;P&gt;I am getting an error when using the following regex&lt;BR /&gt;&lt;BR /&gt;(?&amp;lt;=on\s)(.*)(?=\sby Firewall Settings)&lt;BR /&gt;&lt;BR /&gt;The error is "&lt;SPAN&gt;Error in 'rex' command: regex="(?&amp;lt;=on\s)(.*)(?&amp;lt;HostName&amp;gt;.*)(?=\sby Firewall Settings)" has exceeded configured match_limit, consider raising the value in limits.conf."&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Is there a better way to do this,&amp;nbsp; I am trying to find all text between "on " and " by Firewall Settings.&amp;nbsp; It works in regex101.com, but I get that error in Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 00:52:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Optimize-Regex/m-p/679222#M232194</guid>
      <dc:creator>secphilomath1</dc:creator>
      <dc:date>2024-03-01T00:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Optimize Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Optimize-Regex/m-p/679224#M232195</link>
      <description>&lt;P&gt;It would help to have a sample (sanitized) event to work with.&lt;/P&gt;&lt;P&gt;Avoid lookbehind and lookahead in Splunk.&amp;nbsp; They're costly and rarely necessary.&amp;nbsp; Try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;on\s(?&amp;lt;HostName&amp;gt;\S*)\sby Firewall Settings&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 01 Mar 2024 01:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Optimize-Regex/m-p/679224#M232195</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-01T01:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Optimize Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Optimize-Regex/m-p/679324#M232224</link>
      <description>&lt;P&gt;Good to know, thanks, works perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 17:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Optimize-Regex/m-p/679324#M232224</guid>
      <dc:creator>secphilomath1</dc:creator>
      <dc:date>2024-03-01T17:25:25Z</dc:date>
    </item>
  </channel>
</rss>

