Splunk Search

Case insensitive search in rex

Naren26
Path Finder

I am having a field such as Exception: NullReferenceException. And sometimes, EXCEPTION:NullReferenceExcpetion.

I need to capture the exception type with single rex command. I used the following rex, but it is not working:

rex "(?!)Exception:(?<ErrorType>.*)"

What am I doing wrong here? Is it possible to achieve? Kindly advice.

0 Karma
1 Solution

mayurr98
Super Champion

hey @Naren26
I think you have mistakenly written ! instead of i.
Your regex is correct just change (?!) with (?i)

So your regex would be

rex "(?i)Exception:(?<ErrorType>.*)"

let me know if this helps!

View solution in original post

mayurr98
Super Champion

hey @Naren26
I think you have mistakenly written ! instead of i.
Your regex is correct just change (?!) with (?i)

So your regex would be

rex "(?i)Exception:(?<ErrorType>.*)"

let me know if this helps!

Naren26
Path Finder

Oh my!! Such a silly mistake. Thanks for picking it up.

tiagofbmm
Influencer

Hey

Here is your regex | rex field=t "(?i)Exception(?<lalal>.*)"

Try it in this generic example please:

| makeresults 
| eval t="Exception_asdasd" | append [ | makeresults | eval t="EXCEPTION_asdasd"]
| rex field=t "(?i)Exception(?<lalal>.*)"
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...