Splunk Search

Regular expression for international characters

mahbs
Path Finder

Hi,

I've written a regular expression to capture international characters, the only trouble I'm having with it now is setting the limit on the length of the character.

This is what I have:

[^\p{""}$]{0,3}

I've been using the following site to validate it:
https://www.regextester.com/21

Please help!

Tags (1)
0 Karma

elliotproebstel
Champion

Adapting to SPL from this post:
https://stackoverflow.com/questions/24143150/regex-help-for-alphanumeric-and-international-character...

I think this should work:

| stats count 
| eval tf="Baum -$&*( 5 Steine hoch groß 3 Stück grün****" 
| rex field=tf max_match=0 "(?<int_chars>(\p{L}))"
0 Karma

elliotproebstel
Champion

Just to be clear: the first two lines just set up some dummy data. The only part you'd really need is the regex:
"(?<int_chars>(\p{L}))"

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should provide some sample data to test this against

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...