Splunk Search

How to extract a field value which have combination of number and special characters?

akarivaratharaj
Communicator

I have a field which have values only with numbers and also with combination of number and special characters as values. I would like to filter the field values where both number and special characters are in it.

Example:
Log 1 -> field1="238_345$345"

Log 2 -> field1="+739-8883

Log 3 -> field1="542.789#298"

Already I have tried in writing regex query but there is no expression to filter out the combination of digits & special characters. (No expression to filter all the special character).

How can I filter and display the field value which have the combination of number and special characters? Could anyone help me on this?

Labels (2)
0 Karma

SinghK
Builder
[+\-0-9#$%^!._?@]

 character class 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Are you sure you want _any_ special character? How do you even define a special character in this case?

I'd rather go either for any non-space character and use

\S

or explicitly define set of acceptable character using character class. Like

[-0-9#$%^!.?@]
0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...