Cribl - Docs

Getting started with Cribl LogStream

Questions? We'd love to help you! Meet us in #cribl (sign up)

Changelog    Guides

Regex Extract Function


The Regex Extract function extract fields with regex named groups. These will be index-time fields for Splunk events. Fields that start with __ (double underscore) are special fields in Cribl. They are ephemeral and can be used by any function downstream but will not be added to events and will not exit the pipeline.


Filter: Filter expression (JS) that selects data to be fed through the function. Defaults to empty - all events will be evaluated.

Description: Simple description about this function. Defaults to empty.

Final: If true, stops data from being fed to the downstream functions. Defaults to No.

Regex: Regex literal with named capturing groups, e.g. /(?<foo>bar)/i. Defaults to empty.

Source Field: Field where to perform regex field extraction. Defaults to _raw.

Examples (coming soon)