Splunk Search

regex help - transforms.conf

jlmoldan
New Member

The goal is to take my ohs logs and dump all except entries with IP addresses. IP's w/o images that is. I can get it to only give me the ip addresses but I also want to dump all references to images. Any ideas on how the end of the regex should look?

props.conf

[source::/u01/app/oracle/Middleware/asinst_1/diagnostics/logs/OHS/ohs1/*]
TRANSFORMS-set = setnull,setparsing

transforms.conf

[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[setparsing]
REGEX = \b\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}\b [^.(jpg|gif|png)]
DEST_KEY = queue
FORMAT = indexQueue

Tags (1)
0 Karma

agarrison
Path Finder

Do you have a few example events?

0 Karma

sowings
Splunk Employee
Splunk Employee

It's related to the formatting on this forum; you'll have to either double-up any backslashes, or indent them so that the renderer interprets it as "code".

0 Karma

jlmoldan
New Member

I have no idea what that means. (sorry, new-er to Splunk)

0 Karma

Ayn
Legend

I'm guessing your formatting is a bit broken. Could you please indent all code sections that should be shown as-is with 4 spaces at the start of the line, so that your regex is shown correctly.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...