I have a long query, in it I'm doing rex to extract fields but i need to make rex, flexible depending on data source.
Because depending on the data source I will have to use different regex, and I am wondering if there is anyway to store all of my predefined regex and assign them a token to be able to call upon later within a query.
Go to Settings -> Fields -> Field Extractions. There you can store field extractions for sourcetype, source, or host values that will then get applied to every search you run without a need to call rex over and over.
Go to Settings -> Fields -> Field Extractions. There you can store field extractions for sourcetype, source, or host values that will then get applied to every search you run without a need to call rex over and over.