- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Error: Regex: Missing Closing Parenthesis
mahesh27
Communicator
09-22-2024
05:12 PM
With following search getting error as Missing Closing Parenthesis in splunk.
tried same rex in regex101 it was working.
index=digitalguardian "appStatus"
|rex ,\\"appStatus\\":\\"(?<status>\w+\s\w+)\\"
2024-02-21 {\"callCenterrecontactevent\":{\"customer\":{\"id\":\"6ghty678h\", \"idtypecd\":\"connect_id\"}, \"languagecd\":\"eng\",\"vhannelInstance\":: {\"status\":{\"serverStatusCode\":\"400\",\"severity\":\"Error\",\"additionalStatus\":[{\"statusCode\":400, \"appStatus\":\"Schema Validation\",\"serverity\":\"Error\"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-22-2024
05:40 PM
First, the regular expression in the rex command must be enclosed in quotation marks.
Second, you're being caught by rex's escape trap. Embedded quotation marks must be escaped, but the multiple levels of parsing in SPL call for 3 escape characters.
| rex ", \\\\\"appStatus\\\\\":\\\\\"(?<status>\w+\s\w+)\\\\\""
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
