Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Regex not working as expected

$
0
0
For one of the Security usecase, we need to extract Group Memberships from the Domain\. The trickier part is some of the Group Memberships doesnt have domain name in front of it. I am attaching the Regex link which is working fine on Regex101- https://regex101.com/r/X2YAAd/1 but for some strange reasons, when i use the same regex on Splunk its not working. This is to extract Group membership on EventCode=**4627** Could anyone help me here..

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>