Getting Data In

How to edit my regular expression to retrieve the first 7-8 characters of variable length strings that end with abcd.com?

christopheryu
Communicator

I am trying to extract router names from syslog messages.

Need the regular expression to get the first 7 or 8 characters of variable length strings that end with abcd.com. Example below:

tpbjm01-re0.abcd.com
xtsdjm01-re0.abcd.com
lnd2j902-re1.abcd.com
pqrjm02-re1.abcd.com
py3jm01-re1.uk.abcd.com
brhmjm02-re1.emea.abcd.com
rcnj902.abcd.com
cpzyjm01.abcd.com

So result should be:

tpbjm01
xtsdjm01
lnd2j902
pqrjm02
py3jm01
brhmjm02
rcnj902
cpzyjm01

This is supposed to be the correct regex but it is not pulling anything:

^(?\w{7,8})(?=.*abcd.com)
0 Karma
1 Solution

christopheryu
Communicator

Thank you for the response @rrowland . I did use regex101 in coming up with regex in my question but it does not work with splunk. I was able do it by splunk's "extract new field" and using add/remove events. Regex below:

^(?:[^:\n]*:){4}\d+\s+(?P\w+)

View solution in original post

christopheryu
Communicator

Thank you for the response @rrowland . I did use regex101 in coming up with regex in my question but it does not work with splunk. I was able do it by splunk's "extract new field" and using add/remove events. Regex below:

^(?:[^:\n]*:){4}\d+\s+(?P\w+)

rrowland
Explorer

Hello Christopher,

I was able to use the following on regex101.com with your data set and get your required results using the below.

([a-zA-Z0-9]{7,8})

Regards,
Rich

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...