Splunk Search

where i can learn regular expressions to use them and to create my own regex

dilstn
Explorer

I really need of some knowledge about regular expression ,, as how to create own regex or rex ... so suggest me some tips to learn from the scratch for regular expression

Tags (1)
0 Karma
1 Solution

dart
Splunk Employee
Splunk Employee

The Field Extractor app on Splunkbase contains a regular expression reference which you can check if you hit the edit link on any of the extractions, which will give you examples and you could start by modifying them.

For more of a step by step tutorial, Zed Shaw's Learn Regex the Hard way is a great course to follow.

A reasonable reference exists in the Regular Expressions Info site, which has a quick start, tutorial and pages covering 'advanced' topics such as lookbehind.

View solution in original post

Ayn
Legend

There are some pretty good resources online.

Also you might want to grab a book. "Mastering Regular Expressions" is nice for instance: http://www.amazon.com/Mastering-Regular-Expressions-Jeffrey-Friedl/dp/0596528124/

Rocket66
Communicator

RegExr is an awesome tool! I like it!

0 Karma

dart
Splunk Employee
Splunk Employee

The Field Extractor app on Splunkbase contains a regular expression reference which you can check if you hit the edit link on any of the extractions, which will give you examples and you could start by modifying them.

For more of a step by step tutorial, Zed Shaw's Learn Regex the Hard way is a great course to follow.

A reasonable reference exists in the Regular Expressions Info site, which has a quick start, tutorial and pages covering 'advanced' topics such as lookbehind.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...