Splunk Search

What's the easiest way to Regex for any characters in the middle?

nessaner
Explorer

Hello, I need to take events with two kind of text (different paths) :

Appended to:  G:\Streamserve\
Appended to:  D:\G_volume\Streamserve\

As you can see the is part in the middle that should be different (I have only those 2 kind of cases). I tried with \S* as non whitespace characters but it's not working.  
sth like this
Appended to: \w?:\\(G_volume)*\\*Streamserve

What's is the easiest way to do it? 

Thanks fo the help

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You are almost there - try this

Appended to: +\w?:\\+(G_volume)*\\*Streamserve

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

You are almost there - try this

Appended to: +\w?:\\+(G_volume)*\\*Streamserve

nessaner
Explorer

Thank you so much, it works!

Can I have one question tho? What "+" before  \w means? I know after something it means there is a match one or more times.
In this case Is it for whitespace? the /s+ would mean the same then?
Again, Thank you!!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Correct - from your examples there were multiple (2) spaces between the first colon and the drive letter

Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...