Splunk Search

Incorporate something like this into a Splunk search builder (module)?

matt_1
Explorer

There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a splat. What's the possibility of a search builder along a similar construct as "http://www.regexmagic.com/benefits.html". If it weren't for RegexBuddy and RegexCoach, life would be a lot more difficult. Normal users wouldn't want to mess around with things like these. Even if they were motivated, who knows what they would be scheduling or running on the search bar.

Tags (2)
1 Solution

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

View solution in original post

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...