Splunk Enterprise Security

Need urgent help to filter out logs

Yadukrishnan
Explorer

Hi,

Splunk which I am currently using has all of a sudden increased the log size consumption which has led to my license crossing the threshold. Only have two more warnings left. Have identified a way to filter out some of the Azure logs using regex on the logs. But for some reason the regex is not working. Can someone please help me why this regex is not working. While tested the regex it seems to be working fine but still logs are not getting filtered out even if it matches the criteria. 

I tested my regex in the online site regex101 and the content seems to match the regex. But still logs are not getting filtered out. Can someone please guide me what would be the reason. 

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...