Splunk Search

What regex search could I use to find fields that contain exactly 6 digits?

Piggyy
New Member

I need to search for fields that contain exactly 6 digits.

For example, it should return fields that contain "123456".

I'm currently trying regex_raw="\d{6}" but I think I'm missing something or doing something wrong. Any help would be appreciated!

Tags (2)
0 Karma

johnnyfrx
Path Finder

Something like this might work

(?<!\d)\d{6}(?!\d)

mayurr98
Super Champion

Try this

<your search query> | rex field=_raw "(?<six>\d{6})" | search six=*

let me know if this helps!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

regex "\d{6}" should work. What results are you getting? Can you share the full query in case the problem lies elsewhere?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...