Getting Data In

What's wrong with this REGEX?

danielbb
Motivator

I have this "innocent" regex to send to the nullQueue in transforms.conf, and it doesn't work. I'm scratching my head for two days, what can this be?

REGEX = \} OnChange

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @danielbb ,

as also @livehybrid said, it's mandatory to have a sample of your logs to check your regex, even if it's very simple.

One additional question: what's the flow of your data?

To correctly work this transformation must be located in the first full Splunk instance where logs pass through, in other words in the first Heavy Forwarder.

Ciao.

Giuseppe

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @danielbb 

Are you able to post a sample of the event you are working with and also how you are calling the REGEX/transform?

Does this make any difference?

REGEX = \}\sOnChange

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

danielbb
Motivator

Hi @livehybrid ,

Thank you for the great response.

It seemed to have been a simple typo on my side.

Do you know how I could rework this REGEX to work for multiple phrases (about 50 or so)?

Is it best practice to do it all in one REGEX statement or split it into multiple transforms.conf stanzas?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, performance-wise one transform with a well-crafted regex should be faster than several dozens of separate ones. The question is whether you'll need to maintain that later because a single humongous regex can be very confusing and prone to errors on edit.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...