Splunk Search
Highlighted

Is there any regular expression character limit on Splunk?

Path Finder

Is there any regex limit on Splunk?
Where can I configure its limit?

I have very specific regex formula and it contains long characters..
The formula pattern looks like this: (A1.*A2)|(B1.*B2)|(C1.*C2)|... and so on....

My question is simple, I hope its clear enough...

0 Karma
Highlighted

Re: Is there any regular expression character limit on Splunk?

Legend

Hi deodion,
there aren't limits to regex lenght, the only limit I encountered is the lenght of an URL displayed by a browser: it depends by browser but it should be around 2048,.
Bye.
Giuseppe

0 Karma
Highlighted

Re: Is there any regular expression character limit on Splunk?

Splunk Employee
Splunk Employee

@deodion - Did the answer provided by cusello help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma
Highlighted

Re: Is there any regular expression character limit on Splunk?

Communicator
0 Karma