Splunk Search

where can i set max_match option ?

rakesh_498115
Motivator

Hi ..

For all the regular expression fields created using rex command , there is option called max_match to match all the occurrences of the rex field. Can i know where we will define this option ..to reflect to all the rex fields..

In my props.conf..
i have something like this

EXTRACT-myapps:(?[^<]*)<

So for this field ProductName i want to increase the max_match count or i need to keep max_match = 0 to match all the occurences possible....
Query used with max_match :

sourcetype="myapps" | rex max_match=0 "(?[^<]*)<" | top ProductName

If i give it query its working but i need to know whether i can give in my conf files..please help..

Tags (1)
1 Solution

jonuwz
Influencer

You can't.

You need to move the extraction to transforms.conf, and specify MV_ADD=true

I dont think you can specify a max_matches, it'll just find them all.

docs

View solution in original post

jonuwz
Influencer

You can't.

You need to move the extraction to transforms.conf, and specify MV_ADD=true

I dont think you can specify a max_matches, it'll just find them all.

docs

rakesh_498115
Motivator

yeah its really.. 🙂

0 Karma

jonuwz
Influencer

good man. the world of transform opens up a world of possibilities

0 Karma

rakesh_498115
Motivator

Thanks jonuwz..I finally managed to get it...:)

0 Karma

jonuwz
Influencer

You try it, and if you get stuck, post what you tried, and why it didn't work.

rakesh_498115
Motivator

oh..in that case can you transform my rex above to transforms.conf pls..

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...