<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regular Expression in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regular-Expression/m-p/698057#M237093</link>
    <description>&lt;P&gt;HI , I want to extract purple part. But Severity can be Critical as well .&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[&lt;SPAN class=""&gt;Time:29-08@17:52:05.880&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569130&lt;/SPAN&gt;] &lt;SPAN class=""&gt;17:52:28.604&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt; &lt;SPAN class=""&gt;local0.notice&lt;/SPAN&gt; [&lt;SPAN class=""&gt;S=2952486&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;RAISE-ALARM&lt;/SPAN&gt;:acBoardEthernetLinkAlarm:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;KOREASBC1&lt;/SPAN&gt;] &lt;SPAN class=""&gt;Ethernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;link&lt;/SPAN&gt; &lt;SPAN class=""&gt;alarm.&lt;/SPAN&gt; &lt;SPAN class=""&gt;LAN&lt;/SPAN&gt; &lt;SPAN class=""&gt;port&lt;/SPAN&gt; &lt;SPAN class=""&gt;number&lt;/SPAN&gt; &lt;SPAN class=""&gt;3&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;down.&lt;/SPAN&gt;; &lt;FONT color="#CC99FF"&gt;&lt;SPAN class=""&gt;Severity:minor&lt;/SPAN&gt;&lt;/FONT&gt;; &lt;SPAN class=""&gt;Source:Board#1/EthernetLink#3&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Unique&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:206&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info1:GigabitEthernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;4/3&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info2:SEL-SBC01&lt;/SPAN&gt;; [&lt;SPAN class=""&gt;Time:29-08@17:52:28.604&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569131&lt;/SPAN&gt;] &lt;SPAN class=""&gt;17:52:28.605&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt; &lt;SPAN class=""&gt;local0.warning&lt;/SPAN&gt; [&lt;SPAN class=""&gt;S=2952487&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;RAISE-ALARM&lt;/SPAN&gt;:acEthernetGroupAlarm:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;KOREASBC1&lt;/SPAN&gt;] &lt;SPAN class=""&gt;Ethernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;Group&lt;/SPAN&gt; &lt;SPAN class=""&gt;alarm.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Ethernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;Group&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;Down.&lt;/SPAN&gt;; &lt;FONT color="#CC99FF"&gt;&lt;SPAN class=""&gt;Severity:major&lt;/SPAN&gt;&lt;/FONT&gt;; &lt;SPAN class=""&gt;Source:Board#1/EthernetGroup#2&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Unique&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:207&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info1:&lt;/SPAN&gt;; [&lt;SPAN class=""&gt;Time:29-08@17:52:28.605&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569132&lt;/SPAN&gt;] &lt;SPAN class=""&gt;17:52:28.721&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt; &lt;SPAN class=""&gt;local0.notice&lt;/SPAN&gt; [&lt;SPAN class=""&gt;S=2952488&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;SYS_HA:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Redundant&lt;/SPAN&gt; &lt;SPAN class=""&gt;unit&lt;/SPAN&gt; &lt;SPAN class=""&gt;physical&lt;/SPAN&gt; &lt;SPAN class=""&gt;network&lt;/SPAN&gt; &lt;SPAN class=""&gt;interface&lt;/SPAN&gt; &lt;SPAN class=""&gt;error&lt;/SPAN&gt; &lt;SPAN class=""&gt;fixed.&lt;/SPAN&gt; [&lt;SPAN class=""&gt;Code:0x46000&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;Time:29-08@17:52:28.721&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569133]&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2024 10:55:10 GMT</pubDate>
    <dc:creator>Siddharthnegi</dc:creator>
    <dc:date>2024-09-03T10:55:10Z</dc:date>
    <item>
      <title>Regular Expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regular-Expression/m-p/698057#M237093</link>
      <description>&lt;P&gt;HI , I want to extract purple part. But Severity can be Critical as well .&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[&lt;SPAN class=""&gt;Time:29-08@17:52:05.880&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569130&lt;/SPAN&gt;] &lt;SPAN class=""&gt;17:52:28.604&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt; &lt;SPAN class=""&gt;local0.notice&lt;/SPAN&gt; [&lt;SPAN class=""&gt;S=2952486&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;RAISE-ALARM&lt;/SPAN&gt;:acBoardEthernetLinkAlarm:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;KOREASBC1&lt;/SPAN&gt;] &lt;SPAN class=""&gt;Ethernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;link&lt;/SPAN&gt; &lt;SPAN class=""&gt;alarm.&lt;/SPAN&gt; &lt;SPAN class=""&gt;LAN&lt;/SPAN&gt; &lt;SPAN class=""&gt;port&lt;/SPAN&gt; &lt;SPAN class=""&gt;number&lt;/SPAN&gt; &lt;SPAN class=""&gt;3&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;down.&lt;/SPAN&gt;; &lt;FONT color="#CC99FF"&gt;&lt;SPAN class=""&gt;Severity:minor&lt;/SPAN&gt;&lt;/FONT&gt;; &lt;SPAN class=""&gt;Source:Board#1/EthernetLink#3&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Unique&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:206&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info1:GigabitEthernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;4/3&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info2:SEL-SBC01&lt;/SPAN&gt;; [&lt;SPAN class=""&gt;Time:29-08@17:52:28.604&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569131&lt;/SPAN&gt;] &lt;SPAN class=""&gt;17:52:28.605&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt; &lt;SPAN class=""&gt;local0.warning&lt;/SPAN&gt; [&lt;SPAN class=""&gt;S=2952487&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;RAISE-ALARM&lt;/SPAN&gt;:acEthernetGroupAlarm:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;KOREASBC1&lt;/SPAN&gt;] &lt;SPAN class=""&gt;Ethernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;Group&lt;/SPAN&gt; &lt;SPAN class=""&gt;alarm.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Ethernet&lt;/SPAN&gt; &lt;SPAN class=""&gt;Group&lt;/SPAN&gt; &lt;SPAN class=""&gt;2&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;Down.&lt;/SPAN&gt;; &lt;FONT color="#CC99FF"&gt;&lt;SPAN class=""&gt;Severity:major&lt;/SPAN&gt;&lt;/FONT&gt;; &lt;SPAN class=""&gt;Source:Board#1/EthernetGroup#2&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Unique&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:207&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Info1:&lt;/SPAN&gt;; [&lt;SPAN class=""&gt;Time:29-08@17:52:28.605&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569132&lt;/SPAN&gt;] &lt;SPAN class=""&gt;17:52:28.721&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.82.10.245&lt;/SPAN&gt; &lt;SPAN class=""&gt;local0.notice&lt;/SPAN&gt; [&lt;SPAN class=""&gt;S=2952488&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;BID=d57afa:30&lt;/SPAN&gt;] &lt;SPAN class=""&gt;SYS_HA:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Redundant&lt;/SPAN&gt; &lt;SPAN class=""&gt;unit&lt;/SPAN&gt; &lt;SPAN class=""&gt;physical&lt;/SPAN&gt; &lt;SPAN class=""&gt;network&lt;/SPAN&gt; &lt;SPAN class=""&gt;interface&lt;/SPAN&gt; &lt;SPAN class=""&gt;error&lt;/SPAN&gt; &lt;SPAN class=""&gt;fixed.&lt;/SPAN&gt; [&lt;SPAN class=""&gt;Code:0x46000&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;Time:29-08@17:52:28.721&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;60569133]&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 10:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regular-Expression/m-p/698057#M237093</guid>
      <dc:creator>Siddharthnegi</dc:creator>
      <dc:date>2024-09-03T10:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Regular Expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regular-Expression/m-p/698061#M237096</link>
      <description>&lt;P&gt;&lt;A href="https://regex101.com/r/Op8H3R/1" target="_blank"&gt;https://regex101.com/r/Op8H3R/1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 11:02:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regular-Expression/m-p/698061#M237096</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-09-03T11:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Regular Expression</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regular-Expression/m-p/743528#M241104</link>
      <description>&lt;P&gt;below also give same results, please let me know if its right too..&lt;/P&gt;&lt;P&gt;"(?&amp;lt;severity&amp;gt;Severity:\w+;)"&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 13:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regular-Expression/m-p/743528#M241104</guid>
      <dc:creator>okumar1</dc:creator>
      <dc:date>2025-04-04T13:39:00Z</dc:date>
    </item>
  </channel>
</rss>

