Archive

How do I get Sampledata.zip indexed into Windows based Splunk?

Motivator

Hi

I was trying to go thru Splunk Tutorial, but now I am having trouble in getting sampledata.zip indexed using the host regex shown in the Splunk Tutorial page. My Splunk is on Windows.

Sampledata.zip:./([^/]+)/

http://docs.splunk.com/Documentation/Splunk/latest/User/Adddatatutorial

Is this regex good for Windows Splunk?

Thanks,

Tags (1)
0 Karma
1 Solution

Motivator

In 4.3.2, I confirmed this is working for both type of OS.

  • For Unix OS : Sampledata.zip:./([^/]+)/
  • For Windows : Sampledata.zip:.\\([^/]+)/

** The regex in Tutorial Doc is not working, be careful.

View solution in original post

0 Karma

Motivator

In 4.3.2, I confirmed this is working for both type of OS.

  • For Unix OS : Sampledata.zip:./([^/]+)/
  • For Windows : Sampledata.zip:.\\([^/]+)/

** The regex in Tutorial Doc is not working, be careful.

View solution in original post

0 Karma

Motivator

No as path where it will be extracted will be \ rather than / then try :

Sampledata\.zip:.\\([^\\]+)\\

Motivator

Well, the regex in tutorial is not working.

0 Karma

Motivator

I saw regex for windows in tutorial, thank you!

0 Karma