Skip to main content Link Search Menu Expand Document (external link)

Utility Functions - regexp

Table of contents
  1. regexp


  • regexp(pattern, field)
search sContent("@event_type", "@azureSignIn")
let {username="userPrincipalName"}=f("@azureSignIn")
let {}=regexp("(?<name>.*)@(?<domain>.*)",username)

In this example, the command regexp extracts the captured “named group” from the regular expression pattern. For username “”, two new columns “name” and “domain” are added with value “foo” and “”.