Splunk Search

help in a regular expression extraction

royimad
Builder

I have a text that contains anything followed by a word that start with either
XPOS, POS and HF and ended by -

Example:
ABC XPOS2024 -
DEF POS340903 -
GHI HF3948329 -
...

How to extract XPOS2024 , POS340903 , HF3948329 using regular expression?

Tags (3)
0 Karma

dishasaxena
Path Finder

You may try below regex as well:
"(?:)[^ ]+ +(?P(XPOS|POS|HF)[^ ]+) +-"

If it does not work please let me know.

Regards,
Disha

royimad
Builder

Thanks man

0 Karma

yannK
Splunk Employee
Splunk Employee

try this on the search : (and remove the underscored, they are here to trick the html formatting)


* | rex "(?<myfield>(XPOS|POS|HF)\d+)" | table myfield

royimad
Builder

It's working great thank you guys

0 Karma

yannK
Splunk Employee
Splunk Employee

Thanks Åynm I had a missing parenthesis.

And if the characters after are not always digits, disha's regex is perfect.

0 Karma

Ayn
Legend

* | rex "(?<myfield>(XPOS|POS|HF)\d+)" | table myfield

royimad
Builder

it seems that this isn't working

0 Karma

royimad
Builder

I'm receiving this error

0 Karma

royimad
Builder

Error in 'rex' command: Encountered the following error while compiling the regex '?(XPOS|POS|HF)\d+)': Regex: nothing to repeat

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...