Dashboards & Visualizations

Error: Regex: Missing Closing Parenthesis

mahesh27
Communicator

With following search getting error as Missing Closing Parenthesis in splunk.
tried same rex in regex101 it was working.

index=digitalguardian "appStatus"
|rex ,\\"appStatus\\":\\"(?<status>\w+\s\w+)\\"

 

2024-02-21 {\"callCenterrecontactevent\":{\"customer\":{\"id\":\"6ghty678h\", \"idtypecd\":\"connect_id\"}, \"languagecd\":\"eng\",\"vhannelInstance\":: {\"status\":{\"serverStatusCode\":\"400\",\"severity\":\"Error\",\"additionalStatus\":[{\"statusCode\":400, \"appStatus\":\"Schema Validation\",\"serverity\":\"Error\"

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

First, the regular expression in the rex command must be enclosed in quotation marks.

Second, you're being caught by rex's escape trap.  Embedded quotation marks must be escaped, but the multiple levels of parsing in SPL call for 3 escape characters.

| rex ", \\\\\"appStatus\\\\\":\\\\\"(?<status>\w+\s\w+)\\\\\""
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...