Dashboards & Visualizations

Error: Regex: Missing Closing Parenthesis

mahesh27
Communicator

With following search getting error as Missing Closing Parenthesis in splunk.
tried same rex in regex101 it was working.

index=digitalguardian "appStatus"
|rex ,\\"appStatus\\":\\"(?<status>\w+\s\w+)\\"

 

2024-02-21 {\"callCenterrecontactevent\":{\"customer\":{\"id\":\"6ghty678h\", \"idtypecd\":\"connect_id\"}, \"languagecd\":\"eng\",\"vhannelInstance\":: {\"status\":{\"serverStatusCode\":\"400\",\"severity\":\"Error\",\"additionalStatus\":[{\"statusCode\":400, \"appStatus\":\"Schema Validation\",\"serverity\":\"Error\"

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

First, the regular expression in the rex command must be enclosed in quotation marks.

Second, you're being caught by rex's escape trap.  Embedded quotation marks must be escaped, but the multiple levels of parsing in SPL call for 3 escape characters.

| rex ", \\\\\"appStatus\\\\\":\\\\\"(?<status>\w+\s\w+)\\\\\""
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

&#x1f5e3; You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...