Splunk Search

Regex to match string between 2 strings?

sasank
Explorer

Hi,

I have below splunk command:

| makeresults
| eval _raw="The first value is 0.00 and The second value is 0\",\"origin\":\"rep\",\"source_instance\":\"0\""
| rex "The\sfirst\svalue\sis (?<from>.*) and\sThe\ssecond\svalue\sis (?<to>.*)"

 

This shows the "from" field as 0.00 and "to" field as 0","origin":"rep","source_instance":"0"

In the "to" field I only want the value 0. How do I achieve that?

Labels (1)
0 Karma
1 Solution

PaulPanther
Motivator

@sasank Test your regex in a regex editor like

https://regex101.com/r/1oqLAF/3 

If you follow the link you will find your test string and a regex that you can use to match the correct values.

View solution in original post

0 Karma

sasank
Explorer

Thanks for the link. I couldn't figure out how to match the 2nd value so I am looking if someone can help in fixing the regex

0 Karma

PaulPanther
Motivator

@sasank 

| makeresults
| eval _raw="The first value is 0.00 and The second value is 0\",\"origin\":\"rep\",\"source_instance\":\"0\""
| rex "The\sfirst\svalue\sis (?<from>[^\s]+).+?(?<to>\d)"

0 Karma

PaulPanther
Motivator

@sasank Test your regex in a regex editor like

https://regex101.com/r/1oqLAF/3 

If you follow the link you will find your test string and a regex that you can use to match the correct values.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...