Splunk Search

Regex crash course?

Joffer
Path Finder

Can anyone recommend a good regex crash course article so I can learn how to write my (simple) whitelists and blacklists for my inputs.conf?

2 Solutions

Michael_Wilde
Splunk Employee
Splunk Employee

You might want to check out my video and some of the tools i use.

SplunkNinja - All My Regex's Live in Texas

View solution in original post

jangid
Builder
0 Karma

Alexandre_Nizou
Explorer

If you want to test your regular expressions on the spot, use the online http://www.regexpal.com/.

Take your REGEX and copy it in the first box, take the logs you are trying to match and copy them in the second box... et voila!

0 Karma

dwaddle
SplunkTrust
SplunkTrust

There's not much better on the topic than the O'Reilly book -- http://oreilly.com/catalog/9780596528126/ ... but this is not a "crash course" by any means, it is a full length discussion in great detail.

Given Splunk uses PCRE (Perl Compatible Regular Expressions) I find the "pcrepattern" man page at http://linux.die.net/man/3/pcrepattern to be a useful reference to the advanced features of PCRE.

saurabh_tek11
Communicator

Thanks @dwaddle - i was curious to know, what you answered - Splunk uses PCRE.

0 Karma

lguinn2
Legend

For people who like books, I suggest SAM's Teach Yourself Regular Expressions in 10 Minutes (Ben Forta)

It is reviewed on the regular-expressions info site http://www.regular-expressions.info/book10mins.html

0 Karma

Michael_Wilde
Splunk Employee
Splunk Employee

You might want to check out my video and some of the tools i use.

SplunkNinja - All My Regex's Live in Texas

Joffer
Path Finder

Sweet. RegexBuddy will probably help me alot 🙂

0 Karma

saurabh_tek11
Communicator

@MichaelWilde - kindly update the link, as its not opening now.

0 Karma

wollinet
Path Finder
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...