Splunk Search

Manual Edit of reg expressions in Field Extractions page

lehrfeld
Path Finder

I have been working with extracting userIDs using RegExs and have run into some trouble. The following returns the correct results

| rex field=_raw "\,[abc]\w\w\w\w\w\w(?<userID>)" | stats count(userID)

This extracts user IDs from a csv file (that is our sourcetype)

When I go to the Fields Extraction page and edit the extraction manually, I don't get any results (actually, it returns none found)

I have tried editing the inline regex to read \,[abc]\w\w\w\w\w\w(?) but it is not returning anything. I can't seem to find any documentation about the nuances of this inline regex. Any tips would be great!

Thanks, Mike

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

   | rex  "(,\s)* (?P<userID>\w\w\w\d\d\d\d)(,\s)*"

assumming userId format is 3 alphabet and 4 digits. Update this if necessary.

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this

   | rex  "(,\s)* (?P<userID>\w\w\w\d\d\d\d)(,\s)*"

assumming userId format is 3 alphabet and 4 digits. Update this if necessary.

0 Karma

lehrfeld
Path Finder

That is great! Thank you! Mike

lehrfeld
Path Finder

Thanks for the responses. I have a csv with information like email, userID, phone number, etc in it. A typical userID will be formatted like 'acb1234'. The issue that I am addressing is that the userID location between the various sourcetypes has changed over time. Meaning that in version one, the userID was in the second column, in version two, is has moved to the 8th column.

Sample entry would be
mike@email.com, abc1234, 555-555-1212, FName, LName ...
AND
21, mike@email.com, FName, LName, abc1234, 555-555-1212 etc..

Thank you! Mike

0 Karma

somesoni2
Revered Legend

Can you provide some sample entries?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

There may be some editing error, your userID capturing group cannot match anything because it's empty.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...