Splunk Search

Routing to 3rd party

a212830
Champion

Hi,

I need to route specific messages that come into Splunk to another destination via syslog. I have the props/transforms, but need help with the REGEX. I need to send any event that has "Session started" or "Session ended". Not sure how to wildcard that...

Tags (2)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

A regex of (Session started|Session ended) should meet your need. You can also test things like this out at regexr.com

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

A regex of (Session started|Session ended) should meet your need. You can also test things like this out at regexr.com

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...