Splunk AppDynamics

Logfile Extension and Regular Expressions

Hoosain_Madhi
New Member

how do I use a regular expression to match a pattern in a logfile - I am using LogFile extension

for example from the following line specific to a "Response" msg

{"remoteHost":"epdg","epoch":1648084954231,"command":"Response","Result-Code",{"value":1001}},"statusCode":"2001","status":"FOO ","timestamp":"2022-03-24 03:22:34.231"}

 

can I use a regular expression to find statusCode NOT 2001 indicating a failure - If so what regex should I use?

cant seem to find documentation

 

Labels (1)
0 Karma

Hoosain_Madhi
New Member

After looking at all possible statusCodes the regex I came up with is :

.*"command":"Response".*"statusCode":"[1|3|4|5].*".*

I am not sure on what to put in the config.yml – any ideas?

- displayName: "Diameter-EAP-Response-Failures"

    pattern: "?????"

    matchExactString: false

    caseSensitive: false

    printMatchedString: false

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...