Splunk Search

Incorporate something like this into a Splunk search builder (module)?

matt_1
Explorer

There are some who are really good at regular expression, some okay, and the rest who downright are lost beyond a splat. What's the possibility of a search builder along a similar construct as "http://www.regexmagic.com/benefits.html". If it weren't for RegexBuddy and RegexCoach, life would be a lot more difficult. Normal users wouldn't want to mess around with things like these. Even if they were motivated, who knows what they would be scheduling or running on the search bar.

Tags (2)
1 Solution

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

View solution in original post

dskillman
Splunk Employee
Splunk Employee

For basic users the Splunk Field Extractor (arrow next to each event --> Extract fields) works pretty well. It writes regex for you on the fly and saves it automatically. It's not infallible but the 4.x version is pretty sexy.

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...