Splunk Search

INLINE EXTRACTION with /g option for RegEX

verbal_666
Builder

Hi.
Question:
is there a way to add the classic /g option for RegEX in INLINE RegEX extractor for Splunk (props), without using command rex or other tranformations?

Example,

 

SerialNumber=12345,SerialNumber=67890

 

With a classical regex, "/SerialNumber=(?P<sn>\d+)/g" i can found "12345" & "67890".
Same with an SPL "rex max-match=0 "SerialNumber=(?P<sn>\d+)".
But how to do it in INLINE extraction?

I got rid of the "problem" using extraction of "sn1" & "sn2" fields and transforming them with an eval transformation ("sn = sn1.' , '.sn2") and it works fine. But if, tomorrow, i'll find something like

 

SerialNumber=12345,SerialNumber=67890,SerialNumber=09876,SerialNumber=54321

 


Without the rex i would be in trouble!

Thanks.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried

MV_ADD = true

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried

MV_ADD = true

verbal_666
Builder

Ok with props & transforms solution.
Ticking the "create mv fields", adds the MV_ADD to transforms and does the trick.
I was going to prefer to only use props, but it's ok 👍👍👍

ps. the "(?g)" text in regex INLINE gives errors in regex format.

Thanks all 😊

0 Karma

verbal_666
Builder

Mmmmm... where? 🙄😁 ... in transforms.conf?
So there is no WebIf option to do it?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

have you try to use (?g) on beginning of regex? Another option is use transforms and then MV as @ITWhisperer already proposed.

r. Ismo

0 Karma

verbal_666
Builder

I'll try the "?g" on beginning. I tried the "/g" at the end, but without success 😏
I prefer to only use props and not also transforms.
Thanks anyway.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Like this (?g) or just ?g, brackets is mandatory.
0 Karma
Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...