Splunk Search

Why am I getting this error when using regex for URI search?

ghildiya
Explorer

I have the following query to search results which contain a specific rest endpoint which has a UUID path parameter:

 

 

.... | regex requestURI="/baseurl/\b[0-9a-f]{8}\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\b[0-9a-f]{12}\b

 

 

But it seems to be wrong. Error is :

 

 

Unknown search command '0'.

 

 

What is the mistake I am making here?

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Splunk appears to be interpreting part of your regular expression as a subsearch. Make sure the expression is enclosed in quotation marks and any embedded quotation marks are escaped.
---
If this reply helps you, Karma would be appreciated.
0 Karma

ghildiya
Explorer

I tried this:

.... | regex requestURI=*/baseurl/\"[0-9a-f]{8}\b-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-\b[0-9a-f]{12}\"*

But this too doesn't work. 

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
The regex command is still missing the enclosing quotation marks.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...