Splunk Search

Routing to 3rd party

a212830
Champion

Hi,

I need to route specific messages that come into Splunk to another destination via syslog. I have the props/transforms, but need help with the REGEX. I need to send any event that has "Session started" or "Session ended". Not sure how to wildcard that...

Tags (2)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

A regex of (Session started|Session ended) should meet your need. You can also test things like this out at regexr.com

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

A regex of (Session started|Session ended) should meet your need. You can also test things like this out at regexr.com

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...