Splunk Search

How to write the regex to extract numbers between two hyphens?

jhayIV
Engager

I have the following string 2016-02-17 field and I would like to extract the 02 between the hyphens. Does someone have a regex that will do this?

Tags (2)
0 Karma
1 Solution

vasildavid
Path Finder

Sure,

\d{4}-(?<month>\d{2})-\d{2}

Check out www.regex101.com It can help with building out/learning regular expressions.

View solution in original post

vasildavid
Path Finder

Sure,

\d{4}-(?<month>\d{2})-\d{2}

Check out www.regex101.com It can help with building out/learning regular expressions.

angelo_fazzina
Engager

is it this simple?

\-\d\d\-

\-  = escapes the 1st hyphen
\d\d  =  2 digits
\-  = escapes the 2nd hyphen

-ALF

0 Karma

jhayIV
Engager

Thank you so much I think I messed up the regex command in the search field
I entered the string below in the search field:

rex mode=sed"\d{4}-(?\d{2})-\d{2}"
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...