This is no problem, I use the following site to test my regular expressions:
So it should look something like this:
Note: It is worth noting that this is not a rule, it can be improved.
This option (NO_BINARY_CHECK), according to the link:
NO_BINARY_CHECK = [true|false]
* When set to true, Splunk processes binary files.
* Can only be used on the basis of , or [source::],
* Defaults to false (binary files are ignored).
* This setting applies at input time, when data is first read by Splunk.
The setting is used on a Splunk system that has configured inputs
acquiring the data.
... View more