<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incorrect Regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245189#M73068</link>
    <description>&lt;P&gt;Hi thank you for coming back to me with this, but unfortunately I still receive the same error.&lt;/P&gt;

&lt;P&gt;I'm able to get past the error using rex field=_raw "\"Surname\":\"(?[^\"]+)\"" but it is not extracting any information.&lt;/P&gt;

&lt;P&gt;Kind Regards&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2015 11:34:19 GMT</pubDate>
    <dc:creator>IRHM73</dc:creator>
    <dc:date>2015-11-25T11:34:19Z</dc:date>
    <item>
      <title>Incorrect Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245187#M73066</link>
      <description>&lt;P&gt;Hi, I wonder whether someone may be able to help me please.&lt;/P&gt;

&lt;P&gt;I've created this regex &lt;CODE&gt;\"Surname\\":\\"(?&amp;amp;lt;SName&amp;amp;gt;[^"]+)\\"&lt;/CODE&gt; which extracts the Surname from the following raw data:&lt;/P&gt;

&lt;P&gt;"Surname\":\"SMITH\"&lt;/P&gt;

&lt;P&gt;This works fine in Regex101, but I when I add this to my query here: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;auditSource=tamc auditType=OutboundCall | rex field=_raw "\"Surname\\":\\"(?&amp;lt;SName&amp;gt;[^"]+)\\""
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I receive the following error:  &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Mismatched ']'.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I just wondered whether someone may be able to look at this please and let me know where I've gone wrong.&lt;/P&gt;

&lt;P&gt;Many thanks and kind regards&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 10:53:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245187#M73066</guid>
      <dc:creator>IRHM73</dc:creator>
      <dc:date>2015-11-25T10:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245188#M73067</link>
      <description>&lt;P&gt;Hello try this: &lt;CODE&gt;auditSource=tamc auditType=OutboundCall | rex field=_raw "\"Surname\":\"(?[^\"]+)\""&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 11:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245188#M73067</guid>
      <dc:creator>stephanefotso</dc:creator>
      <dc:date>2015-11-25T11:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245189#M73068</link>
      <description>&lt;P&gt;Hi thank you for coming back to me with this, but unfortunately I still receive the same error.&lt;/P&gt;

&lt;P&gt;I'm able to get past the error using rex field=_raw "\"Surname\":\"(?[^\"]+)\"" but it is not extracting any information.&lt;/P&gt;

&lt;P&gt;Kind Regards&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 11:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245189#M73068</guid>
      <dc:creator>IRHM73</dc:creator>
      <dc:date>2015-11-25T11:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245190#M73069</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Surname":"(?&amp;lt;SName&amp;gt;[^"]+)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;auditSource=tamc auditType=OutboundCall | rex field=_raw "\"Surname\":\"(?&amp;lt;SName&amp;gt;[^\"]+)\""
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 25 Nov 2015 14:10:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245190#M73069</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-11-25T14:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect Regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245191#M73070</link>
      <description>&lt;P&gt;Hi @woodcock thank you for coming back to me with the solution.&lt;/P&gt;

&lt;P&gt;Kind regards&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 14:19:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Incorrect-Regex/m-p/245191#M73070</guid>
      <dc:creator>IRHM73</dc:creator>
      <dc:date>2015-11-25T14:19:53Z</dc:date>
    </item>
  </channel>
</rss>

