Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Splunk Regular Expressions, from Beginning to End
Rating: 4.4 out of 5(26 ratings)
419 students

Splunk Regular Expressions, from Beginning to End

Using Regular Expressions with Splunk | Regex Training for All Versions of Splunk
Last updated 7/2024
English

What you'll learn

  • How to effectively write regular expressions in Splunk
  • Tools and resources that help write regular expressions
  • Special regular expression characters and how they are used
  • Basic understanding of the history and context of regular expressions

Course content

1 section18 lectures2h 54m total length
  • History of regex7:54

    Trace history of regular expressions from Stephen Kleene's 1950s work through grep and sed to POSIX and Perl-compatible regular expressions language, and how Splunk uses regex for log field extraction.

  • What are regular expressions - Lecture8:55

    Discover what regular expressions are and how to use pattern matching to extract fields from logs with capture groups and named capture groups in Splunk.

  • What are regular expressions - Demo17:25

    Explore regex basics with regex101 in this demo. Learn how to choose a flavor, test patterns, and apply literal matching, escaping, and anchors.

  • Highlight resources to use4:58
  • The basic characters to know - Lecture4:50

    Learn the basic regex characters in Splunk, including digit and word classes (\d, \D, \w, \W, \s, \S), ranges with brackets, caret negation, and the period wildcard.

  • The basic characters to know - Demo7:28

    Explore the basic character sets in regular expressions, including digits, word characters, spaces, and the dot wildcard. Learn how ranges and negation control what matches.

  • Quantifiers to Know - Lecture9:46

    Explore quantifiers in regex, including ? optional, * and +, and {n} or {m,n} for precise repeats; apply to phone numbers and social security patterns.

  • Quantifiers to Know - Demo10:52

    Explore quantifiers in regex with practical demos, including optional matches using the question mark, zero or more with the star, one or more with the plus, and curly bracket ranges.

  • Regex Anchors - Lecture7:22

    Master regex anchors for log analysis in Splunk. Use the caret and dollar sign to anchor matches at line starts and ends, and learn \A, \Z, and word boundaries.

  • Regex Anchors - Demo6:40

    Learn to use anchors in regex to accurately capture log entry start and end, using caret and dollar sign to isolate tcp or udp groups in Splunk.

  • Groupings - Lecture12:45

    Learn how regex groupings organize patterns with capturing and non-capturing groups, using parentheses to extract matches and apply quantifiers, with practical IP address examples and regex 101 visualization.

  • Groupings - Demo10:32

    Learn to use capture groups and or operator in regular expressions; turn groups on and off with ?:, and apply anchors to match ip addresses, emails, and timestamps in Splunk.

  • Capture groups and named capture groups - Lecture10:56

    Explore how to create capture groups and name them with the ?<name> syntax, then apply these named fields in Splunk using the rex command to extract date and domain.

  • Capture groups and named capture groups - Demo17:19

    Explore how to build named capture groups in Splunk using regex blocks, demonstrate time, host, user, IP, and port extractions with Rexx, and discuss persistence and search-time limitations.

  • Regex in Splunk – commands - Lecture17:15

    Explore Splunk regular expressions using rex, irex, regex, and eval for extraction, masking, and filtering, and learn how to persist fields via props.conf and transforms.conf.

  • Regex in Splunk – commands _ Demo5:31

    Demonstrates masking IP addresses and port numbers in Splunk using rex substitution, building regex blocks, and filtering underscore raw events with regex to isolate or exclude data.

  • Regex in Splunk – conf files - Lecture4:19

    Explore how to use the field extractor in Splunk Web to create named fields and generate regex patterns, and learn how props.conf and transforms.conf interplay with admin rights.

  • Regex in Splunk – conf files - Demo9:47

    Explore how to build and validate regular expressions in Splunk using the field extractor, highlighting HTTP method, URL, and status code extractions with capture groups.

Requirements

  • You will learn everything you need to know

Description

Splunk Regular Expressions: From Beginning to End

Welcome to Ableversity's comprehensive Splunk Regular Expressions course, taught by our Principal Instructor, Hailie Shaw, and developed under the expert oversight of Michael Bentley, "The Splunk Doctor," one of the most respected Splunkers in the world.

Why This Course Stands Apart

Regular expressions are the secret weapon of Splunk power users, yet they intimidate many professionals. Learning from industry leaders who use regex daily to solve complex data challenges, you'll gain the confidence and practical skills to master this powerful tool. Our instructors break down regex into understandable components, providing real-world examples that demonstrate how regex transforms your ability to extract, validate, and manipulate data in Splunk.

What You'll Master

Through a structured progression from fundamentals to advanced applications, you'll develop complete proficiency in regular expressions within the Splunk context. This course combines clear explanations with hands-on examples, ensuring you learn by doing and can immediately apply your skills to real-world scenarios.

History of Regex: Understand the origins and evolution of regular expressions to appreciate their power and versatility.

What Are Regular Expressions: Grasp the fundamental concepts that underpin all regex operations.

Essential Resources: Discover the tools and resources that will support your regex journey and accelerate your learning.

Basic Characters to Know: Master the foundational building blocks of regex patterns.

Quantifiers to Know: Learn to specify how many times patterns should match for precise data extraction.

Regex Anchors: Control where patterns match within your data for targeted results.

Groupings: Organize complex patterns into manageable components for sophisticated matching.

Capture Groups and Named Capture Groups: Extract specific portions of matched data and reference them efficiently.

Regex in Splunk: Apply everything you've learned specifically within Splunk's search processing language and field extraction tools.

Who Should Enroll

Whether you are a software developer, data scientist, Splunk administrator, or anyone who needs to manipulate text data, this course will provide the skills you need to be successful. Beginners will gain a solid foundation, while those with some regex experience will take their abilities to the next level.

Your Path to Regex Mastery

By the end of this course, you'll possess the confidence and expertise to use regular expressions effectively to solve real-world problems. You'll understand how regex empowers you to perform data validation, complex search and replace operations, advanced field extractions, and sophisticated pattern matching in Splunk.

Join Our Community

Learning doesn't stop when the videos end. Connect with us on LinkedIn, X, and Slack, or visit our website for additional resources and support. We're committed to your success and encourage you to reach out with any questions or concerns. We're here to help you succeed.


Enroll now and take your Splunk regex skills to the next level with the guidance of true industry leaders.

Who this course is for:

  • Those wanting to learn about using regular expressions with Splunk