Splunk Search

Multiple regex expressions for 1 field name

beaunewcomb
Communicator

I have 2 different extractions but their values need to be part of the same field. How can I do that? I've tried using regex groups, using the same field name in both matches but no luck.

Tags (1)
0 Karma

lguinn2
Legend

Do it as two separate extractions:

In props.conf:

EXTRACT-e1=mq-qm(?P<object>[^)]{0,20})
EXTRACT-e2=mpgw(?P<object>[^)]{0,20})

Also, if you want to use parentheses for grouping, you need to specify a non-capturing group.

(?: )

instead of just

( )

Although that wasn't the only problem here...

0 Karma

beaunewcomb
Communicator

To be more clear- what I'm trying to do is create a field from this regex:

mq-qm((?P[^)]{0,20})|mpgw((?P[^)]{0,20})

But I get this error:
Encountered the following error while trying to save: In handler 'props-extract': Regex: two named subpatterns have the same name

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...