Splunk Search

Using regex to filter by file directory

nwalker15
Engager

I have a field in splunk named commandline.  I want to filter this field just by values containing "C:\"

This appears sometimes at the beginning of the filed value and other times in the middle.  Can someone help me with a regex statement or other search filter to narrow my results this way?

Labels (1)
0 Karma
1 Solution

diogofgm
SplunkTrust
SplunkTrust

Use wildcards

commandline=“*C:\*”

------------
Hope I was able to help you. If so, some karma would be appreciated.

View solution in original post

Vardhan
Contributor

Hi @nwalker15 ,

 provide sample logs and highlight the keyword which you want to extract.

0 Karma

diogofgm
SplunkTrust
SplunkTrust

Use wildcards

commandline=“*C:\*”

------------
Hope I was able to help you. If so, some karma would be appreciated.
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...