Splunk Search

How to search keywords to identify in a field using regex?

sathiyasun
Explorer

How to match keywords to identify in a field using regex.

Our requirement is to capture the keywords that are (Liquor OR Casino OR Gambling OR Adult) which comes in a field.

somesoni2
Revered Legend

Try this. To extract a new field with the keyword and filter events where these keywords are present

index=foo sourcetype=bar (Liquor OR Casino OR Gambling OR Adult) | rex field=_raw "(?<somefield>(Liquor|Casino|Gambling|Adult))"
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...