Splunk Search

Help with regex..?

prakash007
Builder

Need help with regex...should start with " end with space or ?

Need entire string in a field starting with " and end until j.prod or c.cat etc...

 "GET /brit-pocket09fress/cprod121000019___/j.prod HTTP/1.1"

  "GET /nprod789jkj908989heys__/j.prod?icid=&searchType=

  "GET /Zin-carsposn-vwlvet-09878__/c.cat HTTP/1.1"
0 Karma
1 Solution

somesoni2
Revered Legend

Try this

your base search |rex field=yourfield "\"(?<SomefieldName>\S+\s+[^\s\?]+)"

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

(?<myCapture>"[^\s]+\s+[^\s?]+)(?<=\/)
0 Karma

prakash007
Builder

some how it's giving me the date when i do | rex field=_raw (?"[^\s]+\s+[^\s?]+)(?<=\/) | table myCapture, _raw

0 Karma

somesoni2
Revered Legend

Try this

your base search |rex field=yourfield "\"(?<SomefieldName>\S+\s+[^\s\?]+)"
0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...