Splunk Search

Rexgex Non-capturing group - still capturing?

tb5821
Communicator
rex field=title "(?titleNEW(.*?)(?:-))"

I have this rex command above but it still outputs the dash at the end which is in a non-capturing group- any help?

Labels (1)
Tags (2)
0 Karma
1 Solution

tb5821
Communicator

Figured this out - by changing where the new field name paranthesie was...

rex field=title "(?<titleNEW>(.*?))(?:-)"

View solution in original post

tb5821
Communicator

Figured this out - by changing where the new field name paranthesie was...

rex field=title "(?<titleNEW>(.*?))(?:-)"

jotne
Builder

Not sure if you have an optimal regex.  Why do you make a non capturing group of "-" and why a capture group in the named group?  This is some better:

rex field=title "(?<titleNEW>.*?):-"

 Even better, do not use * in regex when its not needed.  Do a search until you find some that its not included, like this:

rex field=title "(?<titleNEW>[^-]+)"

 

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...