Splunk Search

Python SDK escaping regular expressions in search

askjoe
Engager

I am running searches via the Python SDK and having issues when I include regular expressions as part of the search. How do I escape the regular expression so the search can run as expected?

The search regex causing issues:

..... | regex http.hostname="\b(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?).){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\b" | .......

The error:

ExpatError: not well-formed (invalid token): line 5, column 148

Basically I'm looking to match IP

Tags (4)

rafamss
Contributor

Hi askjoe,

Do you need help for this question yet?

[]s
Rafael Martins

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...