Splunk Search

Can we put or in 2 regex conditions

aashish_122001
Explorer

Can we put or in 2 regex conditions?

If no, is there any alternative?

for example

index = idx1 | regex name = ^Aa or id = ^101

Tags (2)
0 Karma
1 Solution

mtranchita
Communicator

If I follow your question it should just be a matter of crafting your expression properly
simple example:

index = idx1 | regex name="\w|\d"

Should return results where the value of the field called name is a word or digit character

View solution in original post

0 Karma

mtranchita
Communicator

If I follow your question it should just be a matter of crafting your expression properly
simple example:

index = idx1 | regex name="\w|\d"

Should return results where the value of the field called name is a word or digit character

0 Karma

aashish_122001
Explorer

Can we use upper function also to make the regular expression search case insensitive or is there any other way ?

0 Karma

mtranchita
Communicator

Yes, you should be able to use any valid PCRE.
Splunk's documentation can explain this much better than I:
http://docs.splunk.com/Documentation/Splunk/6.3.0/Knowledge/AboutSplunkregularexpressions

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...