- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
martin_mueller
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
11-25-2014
07:01 AM
Converted from http://answers.splunk.com/answers/193524/how-to-write-a-search-to-return-events-with-a-vari.html
Hi,
i want to extract this field language:
language:ru-ru
can you please help me what regular expression should i write?
Thanks,
Snabel
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
martin_mueller
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
11-25-2014
07:01 AM
Try this:
language:(?<language>\w+-?\w*)
In the long run you should consider setting up key-value extraction around the colon instead of the equals sign.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
martin_mueller
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
SplunkTrust
11-25-2014
07:01 AM
Try this:
language:(?<language>\w+-?\w*)
In the long run you should consider setting up key-value extraction around the colon instead of the equals sign.
data:image/s3,"s3://crabby-images/2762a/2762a549f4986b9f8f4e515ea77f65f7d9fa1fc8" alt=""