Splunk Search

where can i set max_match option ?

rakesh_498115
Motivator

Hi ..

For all the regular expression fields created using rex command , there is option called max_match to match all the occurrences of the rex field. Can i know where we will define this option ..to reflect to all the rex fields..

In my props.conf..
i have something like this

EXTRACT-myapps:(?[^<]*)<

So for this field ProductName i want to increase the max_match count or i need to keep max_match = 0 to match all the occurences possible....
Query used with max_match :

sourcetype="myapps" | rex max_match=0 "(?[^<]*)<" | top ProductName

If i give it query its working but i need to know whether i can give in my conf files..please help..

Tags (1)
1 Solution

jonuwz
Influencer

You can't.

You need to move the extraction to transforms.conf, and specify MV_ADD=true

I dont think you can specify a max_matches, it'll just find them all.

docs

View solution in original post

jonuwz
Influencer

You can't.

You need to move the extraction to transforms.conf, and specify MV_ADD=true

I dont think you can specify a max_matches, it'll just find them all.

docs

rakesh_498115
Motivator

yeah its really.. 🙂

0 Karma

jonuwz
Influencer

good man. the world of transform opens up a world of possibilities

0 Karma

rakesh_498115
Motivator

Thanks jonuwz..I finally managed to get it...:)

0 Karma

jonuwz
Influencer

You try it, and if you get stuck, post what you tried, and why it didn't work.

rakesh_498115
Motivator

oh..in that case can you transform my rex above to transforms.conf pls..

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...