Splunk Search

how to write the regular expression for my statement?

lksridhar
Explorer

Hi folks,

could you please anyone help me to write the regex for below statement and need extract the external value from below logs.

EXTERNAL:10.23.9.121/587327

Tags (1)
0 Karma
1 Solution

adayton20
Contributor

Give this a try:

|rex field=_raw "EXTERNAL\:(?P<EXTERNAL>.[^\s]*)"

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

Try

... my search here | rex field=_raw "EXTERNAL:(?<EXTERNAL>\d+\.\d+\.\d+\.\d+\/\d+)"

You can see it works in this example at regex101.com.

adayton20
Contributor

Give this a try:

|rex field=_raw "EXTERNAL\:(?P<EXTERNAL>.[^\s]*)"
0 Karma

lksridhar
Explorer

thank for the information adayton and i tried with above search and not receiving any value under the External.

0 Karma

zanb
Path Finder

AFAIK shouldn't have to use a backward slash on colons.

0 Karma

lksridhar
Explorer

adayton and zanb , the below command is working fine.

rex field=_raw "EXTERNAL:(?P.[^\s]*)"

0 Karma

adayton20
Contributor

Can you provide a sample of the raw log, please?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...