# Search using regex

**URL:** <https://community.graylog.org/t/search-using-regex/4331>\
**Category:** Graylog Central (peer support)\
**Tags:** sidecar, winlogbeat\
**Created:** [February 23, 2018, 5:13am UTC](https://community.graylog.org/t/search-using-regex/4331 "2018-02-23T05:13:22Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![v\_2nas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/v_2nas/32/268_2.png) [@v\_2nas](https://community.graylog.org/u/v_2nas)\
**Post date:** [February 23, 2018, 5:13am UTC](https://community.graylog.org/t/search-using-regex/4331/1 "2018-02-23T05:13:23Z")

</div>

Hi Folks,

I am searching for specific event (4624) and where targetusername doesn’t match computername.  
The computer accounts in Windows is denoted by a $ at the end of the name.

> [@Regex in search assistance](https://community.graylog.org/t/regex-in-search-assistance/780):
>
> I am trying to build a regex to match strings as follows: PDCS-MBX01$ pluto$ 12-2423$ I tried using the following: winlogbeat\_event\_data\_SubjectUserName:(\w\W)+$ I thought the search should have been: [\w\W]+$, but Graylog does not like the [or] characters. Can anyone assist with a regex that will be accepted by Graylog and match all three of the above string types?

So i used the regex provide in above thread. The regex ([\w-]+$) works when i test in online [regexr.com](http://regexr.com)  
However, when i used in graylog search it failed.

My idea is to exclude all 4624 events where TargetUserName is a computer account.

 ![2018-02-23%2013_09_24-Graylog%20-%20Search](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/14d64eef3961adb8059b4f4dde7c04c15cb53443.png)

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [February 23, 2018, 8:07am UTC](https://community.graylog.org/t/search-using-regex/4331/2 "2018-02-23T08:07:43Z")

</div>

your query did not look like the one that is provided by jochen:

> [@Regex in search assistance](https://community.graylog.org/t/regex-in-search-assistance/780/2):
>
> $ is a special character in regular expressions meaning “end of input”. The following regular expression will match these strings: ([\w-]+\$) You can play around with your regular expressions on pages like [http://www.freeformatter.com/java-regex-tester.html](http://www.freeformatter.com/java-regex-tester.html).

---

<div class="post-metadata">

**Author:** ![v\_2nas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/v_2nas/32/268_2.png) [@v\_2nas](https://community.graylog.org/u/v_2nas)\
**Post date:** [February 23, 2018, 8:30am UTC](https://community.graylog.org/t/search-using-regex/4331/3 "2018-02-23T08:30:11Z")

</div>

This regular expression  
([\w-]+$)  
works with java regex tester

but the same regular expression gives error in graylog search EventID:4624 AND TargetUserName:([\w-]+$)  
Failed to parse query [EventID:4624 AND TargetUserName:([\w-]+$)]  
Failed to parse query [EventID:4624 AND TargetUserName:([\w-]+$)]  
Failed to parse query [EventID:4624 AND TargetUserName:([\w-]+$)]

---

<div class="post-metadata">

**Author:** ![v\_2nas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/v_2nas/32/268_2.png) [@v\_2nas](https://community.graylog.org/u/v_2nas)\
**Post date:** [February 23, 2018, 8:45am UTC](https://community.graylog.org/t/search-using-regex/4331/4 "2018-02-23T08:45:35Z")

</div>

![2018-02-23%2016_45_04-Graylog%20-%20Search](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/6868cf847b8156896aec2912df51790b64bc1e93.png)

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [February 23, 2018, 8:46am UTC](https://community.graylog.org/t/search-using-regex/4331/5 "2018-02-23T08:46:53Z")

</div>

> [@v\_2nas](#):
>
> but the same regular expression gives error in graylog search EventID:4624 AND TargetUserName:([\w-]+$)

Yes, because that’s the wrong query syntax. 😉

Try the following query:

```plaintext
EventID:4624 AND TargetUserName:/.+/

```

Also be reminded that the regular expression has to match _the complete field content_ if the field hasn’t been tokenized/analyzed.

See [Regexp Query | Elasticsearch Reference [5.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/query-dsl-regexp-query.html#regexp-syntax) for details about the Lucene regular expression syntax.

---

<div class="post-metadata">

**Author:** ![v\_2nas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/v_2nas/32/268_2.png) [@v\_2nas](https://community.graylog.org/u/v_2nas)\
**Post date:** [February 23, 2018, 8:57am UTC](https://community.graylog.org/t/search-using-regex/4331/6 "2018-02-23T08:57:41Z")

</div>

i was basing it on the regex i found on the community.  
I don’t have much understanding of the regex, so i do some trial and error using what is available.

([\w-]+) matches the the condition in java regex tester, but as you mentioned, it's incorrect for graylog. i have tried to use \ char for but that didn’t work.

I need to exclude all those events where name contains a computer name preceded by , something like abcd, abcdefg$, etc.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [February 23, 2018, 9:31am UTC](https://community.graylog.org/t/search-using-regex/4331/7 "2018-02-23T09:31:06Z")

</div>

> [@v\_2nas](#):
>
> I don’t have much understanding of the regex, so i do some trial and error using what is available.

That’s why I’ve pointed you to the documentation.

---

<div class="post-metadata">

**Author:** ![v\_2nas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/v_2nas/32/268_2.png) [@v\_2nas](https://community.graylog.org/u/v_2nas)\
**Post date:** [March 9, 2018, 7:36am UTC](https://community.graylog.org/t/search-using-regex/4331/8 "2018-03-09T07:36:07Z")

</div>

I manage to get assistance from another graylog ninja, so thought i will share the solution to help anyone who is in the same situation.  
So, we enabled allow\_leading\_wildcard\_searches=true in the server.conf file  
Then i could use this search query to get all user minus computer accounts.

EventID:4624 AND NOT TargetUserName:\*$

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 23, 2018, 7:36am UTC](https://community.graylog.org/t/search-using-regex/4331/9 "2018-03-23T07:36:11Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
