Splunk Search

Incorporate something like this into a Splunk search builder (module)?

matt_1
Explorer

There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a splat. What's the possibility of a search builder along a similar construct as "http://www.regexmagic.com/benefits.html". If it weren't for RegexBuddy and RegexCoach, life would be a lot more difficult. Normal users wouldn't want to mess around with things like these. Even if they were motivated, who knows what they would be scheduling or running on the search bar.

Tags (2)
1 Solution

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

View solution in original post

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...