Splunk log regex

Published on Tue Mar 01 2022

regex to parse space separated log message from splunk test string ``` ugi=flink ip=172.18.214.55 cmd=source:172.18.214.55 alter_table: hive.net_seed.netdebugnetworkconnectionstatereadysnapshotcapturedevent newtbl=netdebugnetworkconnectionstatereadysnapshotcapturedevent ugi=root ip=172.19.212.146 cmd=source:172.19.212.146 get_table : tbl=hive.nlx_dev.marrsqueryrewritecontextevent ```

Additional matching regexes for
Splunk log regex

Splunk log regex

regex to parse space separated log message from splunk test string ``` ugi=flink ip=172.18.214.55 cmd=source:172.18.214.55 alter_table: hive.net_seed.netdebugnetworkconnectionstatereadysnapshotcapturedevent newtbl=netdebugnetworkconnectionstatereadysnapshotcapturedevent ugi=root ip=172.19.212.146 cmd=source:172.19.212.146 get_table : tbl=hive.nlx_dev.marrsqueryrewritecontextevent ```

Parse CSV fields

Parse an input string into fields separated by comma.

Html tag parser

This regex will help you to parse html tag. Example ```html <!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <title>Title</title> </head> <body> <picture> <source srcset="mobile.png" ></source> <source srcset="tablet.png" ></source> <source srcset="desktop.png" ></source> <img srcset="default.png"> </picture> </body> </html> ``` Output ```html <picture> <source srcset="mobile.png" ></source> <source srcset="tablet.png" ></source> <source srcset="desktop.png" ></source> <img srcset="default.png"> </picture> ```

match arguments similar to shell, supports quoted string

first group matches quoted strings second group plain text, arguments are separated with a space. example: "this is a \"string\"" thisisnot "another \"string\" with a backslash \"\\"" just replace \" with " after matching.

Signature of UNIFI Protect in SPLUNK for DHCP

Pulls the DHCP Command from SPLUNK output

Pokemon Go Discord - friend codes

A regex to parse codes from a discord server

Gitlab - Commit message

Commit message for Gitlab's Push Rules

Task 2, part 1

Finds all source numbers in square brackets

JavaScript trim string regex

Trim leading/trailing space on a string: do not use /gm flags. Trim each line of a multiline string: use the /gm flag.

CSV CIDR subnets

Comma separated CIDR network addresses