Splunk Search

Regex Help

ipops
Path Finder

I am trying to do a field extract but running into problems

Here is an example event. I am trying to build a regex to extract the signatures field (IP Fragmentation, DNS Amplification). The signature can be different for each event so I need to extract everything between the () after the word signatures. Can someone help me with a regex? My attempts are only returning partial events

Sep 19 23:32:49 10.201.1.79 [pfsp] emerg: Host Detection alert #13630, start 2017-09-19 23:31:45 UTC, duration 64, direction incoming, host 1.2.3.4, signatures (IP Fragmentation, DNS Amplification), impact 1.10 Gbps/117.80 Kpps, importance 2, managed_objects ("ARIN-Allocated Prefixes"), (parent managed object "nil")

Sep 20 04:56:50 10.201.1.79 [pfsp] emerg: Host Detection alert #13631, start 2017-09-20 04:56:45 UTC, duration 5, direction incoming, host 1.2.3.4, signatures (IP Fragmentation), impact 133.45 Mbps/21.82 Kpps, importance 1, managed_objects ("ARIN-Allocated Prefixes"), (parent managed object "nil")

Tags (2)
0 Karma
1 Solution

koshyk
Super Champion

is this you looking for?

signatures\s\((?<signature_value>[^\)]+)\)

Example: https://regex101.com/r/3sEpdC/1

So your search would be something like

... | rex  "signatures\s\((?<signature_value>[^\)]+)\)"

View solution in original post

0 Karma

ipops
Path Finder

That worked!

Thanks so much!

0 Karma

koshyk
Super Champion

is this you looking for?

signatures\s\((?<signature_value>[^\)]+)\)

Example: https://regex101.com/r/3sEpdC/1

So your search would be something like

... | rex  "signatures\s\((?<signature_value>[^\)]+)\)"
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...