Splunk Search

Help with Regex

shruti14
Explorer

Hi, Can someone help me with field extraction for string :

/home/mysqld/databasename/audit/audit.log

I want to extract databasename as Database to be used 

i have written regex but getting error, can someone help with correct regex:

rex field=source "\/home\/\/mysqld\//(?<Database>.*)/audit\/"

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It would help to know what error you're getting.

The regex has too many slashes. needs explicit <>, and the slash before "audit" must be escaped.  This works with the example data.

| rex field=source "\/home\/mysqld\/(?<Database>.*)\/audit\/"

  

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It would help to know what error you're getting.

The regex has too many slashes. needs explicit <>, and the slash before "audit" must be escaped.  This works with the example data.

| rex field=source "\/home\/mysqld\/(?<Database>.*)\/audit\/"

  

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...