Splunk Search

regex help - transforms.conf

jlmoldan
New Member

The goal is to take my ohs logs and dump all except entries with IP addresses. IP's w/o images that is. I can get it to only give me the ip addresses but I also want to dump all references to images. Any ideas on how the end of the regex should look?

props.conf

[source::/u01/app/oracle/Middleware/asinst_1/diagnostics/logs/OHS/ohs1/*]
TRANSFORMS-set = setnull,setparsing

transforms.conf

[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[setparsing]
REGEX = \b\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}\b [^.(jpg|gif|png)]
DEST_KEY = queue
FORMAT = indexQueue

Tags (1)
0 Karma

agarrison
Path Finder

Do you have a few example events?

0 Karma

sowings
Splunk Employee
Splunk Employee

It's related to the formatting on this forum; you'll have to either double-up any backslashes, or indent them so that the renderer interprets it as "code".

0 Karma

jlmoldan
New Member

I have no idea what that means. (sorry, new-er to Splunk)

0 Karma

Ayn
Legend

I'm guessing your formatting is a bit broken. Could you please indent all code sections that should be shown as-is with 4 spaces at the start of the line, so that your regex is shown correctly.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...