Splunk Search

regex help

mcbradford
Contributor

Not the best regex king, so I need some help please

within the field "From" in my data there are emails. Within the emails there should never be a number before the @.

For example, mark1@mydamin.com is not valid, but mark@mydomain.com is valid.

I want to find all the non valid emails.

Tags (1)
0 Karma

skoelpin
SplunkTrust
SplunkTrust

Try this..

If you want to get good with regex then go to www.regex101.com and put some sample data in and test it

This will find all emails with a number before the @ symbol

\w+\d@\w+\.com

index=foo ... | rex (?P<Bad_Email>\w+\d@\w+\.com)

0 Karma

sundareshr
Legend

Try this

.... | rex "(.*\d.*?@[^\s]+)" | ...
0 Karma

somesoni2
Revered Legend

Try like this

your base search | regex From="\S+\d\@\S+"
0 Karma
Get Updates on the Splunk Community!

Security Professional: Sharpen Your Defenses with These .conf25 Sessions

Sooooooooooo, guess what. .conf25 is almost here, and if you're on the Security Learning Path, this is your ...

First Steps with Splunk SOAR

Our first step was to gather a list of the playbooks we wanted and to sort them by priority.  Once this list ...

How To Build a Self-Service Observability Practice with Splunk Observability Cloud

If you’ve read our previous post on self-service observability, you already know what it is and why it ...