Splunk Search

How to write a regular expression so that it’s case sensitive and only looks at ABC and not Abc or abc?

abhijit_mhatre
Path Finder

Please let me know the regex for this.
How can the extracted field be modified?

Thanks

1 Solution

gokadroid
Motivator

How about trying this:

(ABC) which matches ABC as a string and does not match Abc or abc see here

[ABC] on the other hand will match either A, B or C see here

[ABC]+ will match any combinations of one or more ABCs like AABBCC, ABC, Abc (A is matched in Abc ) and so on... see here

So please use accordingly.

View solution in original post

0 Karma

gokadroid
Motivator

How about trying this:

(ABC) which matches ABC as a string and does not match Abc or abc see here

[ABC] on the other hand will match either A, B or C see here

[ABC]+ will match any combinations of one or more ABCs like AABBCC, ABC, Abc (A is matched in Abc ) and so on... see here

So please use accordingly.

0 Karma

cmerriman
Super Champion

[ABC] should only look at ABC and not Abc or abc. However, :upper and :lower can be used, and i makes things case insensitive.

you can test regexes here: https://regex101.com/

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...