Splunk Search

Incorporate something like this into a Splunk search builder (module)?

matt_1
Explorer

There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a splat. What's the possibility of a search builder along a similar construct as "http://www.regexmagic.com/benefits.html". If it weren't for RegexBuddy and RegexCoach, life would be a lot more difficult. Normal users wouldn't want to mess around with things like these. Even if they were motivated, who knows what they would be scheduling or running on the search bar.

Tags (2)
1 Solution

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

View solution in original post

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...