Splunk Search

How to write regex to extract different pattern of data

seksit
Explorer

Hi everyone.

I'm new for splunk. I'm learning splunk using splunk's documents in website.

Now I'm learn to splunk scenario lesson of how to extract, when I try to extract fields called username, clientip. But the data has different pattern.

How can I write regex for this pattern?

attached is my extract fields.

Sorry for my english 🙂

alt text

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This regex string should extract the user name or "invalid user x".

"for (?P<username>[\w ]+) from (?P<clientip>[^ ]+)"
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...