如何编写Splunk正则表达式提取CEF日志中fileId前双竖线之间的0
Splunk Regex to Extract Target Value from CEF Log
Got it, let's work through this. You need to pull out the 0 that's sandwiched between the two pipes right before the fileId field in your CEF log entry. Here's how to do it cleanly in Splunk:
The Regex & Splunk Command
Use the rex command with a lookaround-based regex to precisely target that value without capturing extra parts of the log:
... | rex field=_raw "(?<=\|)(?<target_number>\d+)(?=\|\s*fileId=)" | table target_number
How This Regex Works
Let's break down each part to make sure you understand:
(?<=\|): This is a positive lookbehind assertion — it checks that the character immediately before our target value is a pipe (|), but doesn't include that pipe in the match.(?<target_number>\d+): This captures one or more digits into a custom field namedtarget_number(you can rename this to whatever makes sense for your use case, likefileId_preceding_value).(?=\|\s*fileId=): This is a positive lookahead assertion — it verifies that our target value is immediately followed by a pipe, any amount of whitespace (including none), and thefileId=string. Again, this part isn't included in the final captured value.
Testing with Your Log
For your specific CEF entry:
CEF:0|Incapsula|SIEMintegration|1|1|Normal|0| fileId=465000430130063349
This regex will correctly capture the 0 that sits between Normal| and | fileId=.
内容的提问来源于stack exchange,提问作者supriya
相关产品推荐
相关产品推荐

