Regular Expressions 101

Community Patterns

Splunk all but last field extractor

0

Regular Expression
PCRE (PHP <7.3)

/
(?s)datetime:(?<datetime>.*?)\s*\||hostname:(?<hostname>.*?)\s*\||threadId:(?<threadId>.*?)\s*\||userId:(?<userId>.*?)\s*\||correlationId:(?<correlationId>.*?)\s*\||applicationName:(?<applicationName>.*?)\s*\||direction:(?<direction>.*?)\s*\||operationName:(?<operationName>.*?)\s*\||className:(?<className>.*?)\s*\||methodName:(?<methodName>.*?)\s*\||latency:(?<latency>.*?)\s*\||clusterName:(?<clusterName>.*?)\s*\||webServiceType:(?<webServiceType>.*?)\s*\||strCode:(?<strCode>.*?)\s*\||strDescription:(?<strDescription>.*?)\s*\||payload:(?<payload>.*?)\s*\||requestVerb:(?<requestVerb>.*?)\s*\||httpStatusCode:(?<httpStatusCode>.*?)\s*\||httpHeaders:(?<httpHeaders>.*?)\s*\||requestUrl:(?<requestUrl>.*?)\s*\||content\-length:(?<content_length>.*?)\s*\||logMessage:(?<logMessage>.*?)\s*\|
/
gm

Description

no description available

Submitted by anonymous - 6 years ago