Getting Data In

What's wrong with this REGEX?

danielbb
Motivator

I have this "innocent" regex to send to the nullQueue in transforms.conf, and it doesn't work. I'm scratching my head for two days, what can this be?

REGEX = \} OnChange

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @danielbb ,

as also @livehybrid said, it's mandatory to have a sample of your logs to check your regex, even if it's very simple.

One additional question: what's the flow of your data?

To correctly work this transformation must be located in the first full Splunk instance where logs pass through, in other words in the first Heavy Forwarder.

Ciao.

Giuseppe

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @danielbb 

Are you able to post a sample of the event you are working with and also how you are calling the REGEX/transform?

Does this make any difference?

REGEX = \}\sOnChange

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...