Splunk Search

Incorporate something like this into a Splunk search builder (module)?

matt_1
Explorer

There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a splat. What's the possibility of a search builder along a similar construct as "http://www.regexmagic.com/benefits.html". If it weren't for RegexBuddy and RegexCoach, life would be a lot more difficult. Normal users wouldn't want to mess around with things like these. Even if they were motivated, who knows what they would be scheduling or running on the search bar.

Tags (2)
1 Solution

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

View solution in original post

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...