Splunk Search

What's the easiest way to Regex for any characters in the middle?

nessaner
Explorer

Hello, I need to take events with two kind of text (different paths) :

Appended to:  G:\Streamserve\
Appended to:  D:\G_volume\Streamserve\

As you can see the is part in the middle that should be different (I have only those 2 kind of cases). I tried with \S* as non whitespace characters but it's not working.  
sth like this
Appended to: \w?:\\(G_volume)*\\*Streamserve

What's is the easiest way to do it? 

Thanks fo the help

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You are almost there - try this

Appended to: +\w?:\\+(G_volume)*\\*Streamserve

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

You are almost there - try this

Appended to: +\w?:\\+(G_volume)*\\*Streamserve

nessaner
Explorer

Thank you so much, it works!

Can I have one question tho? What "+" before  \w means? I know after something it means there is a match one or more times.
In this case Is it for whitespace? the /s+ would mean the same then?
Again, Thank you!!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Correct - from your examples there were multiple (2) spaces between the first colon and the drive letter

Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...