Splunk Search

How to write a regular expression to list out events with a date in the format dd-mm-yyyy?

Builder

How do I write the regex to list out the events with dd-mm-yyyy ?

where
dd-days
mm-month
yyyy-year

all are digits.

0 Karma
1 Solution

SplunkTrust
SplunkTrust

Perhaps this will get you started.

index=foo | regex "\d\d-\d\d-\d{4}" | ...
---
If this reply helps you, an upvote would be appreciated.

View solution in original post

SplunkTrust
SplunkTrust

\d\d-\d\d-\d\d\d\d

But I take it you want to then convert this to a timestamp or index this with correct timestamps.

0 Karma

SplunkTrust
SplunkTrust

Perhaps this will get you started.

index=foo | regex "\d\d-\d\d-\d{4}" | ...
---
If this reply helps you, an upvote would be appreciated.

View solution in original post

Legend

Can you share some events?

0 Karma