I have a csv file that I am trying to pull data from, this is an example of the data in the file:
Action, Message, Server Connection, Service Path, Service Acct, Source IP, Time, User
Retrieve password,126.259.193.138,(Action: Connect)(Connection to address: aservername01),Operating System-FHR-ServerAdmins-kochind.com-SVCSVRACCESSPROD5,SVCSVRACCESSPROD5,172.16.125.36,07/10/2018 15:45:41,Some.Guy@nowhere.com
My query where I am trying to pull just the server name, "aservername01" out of the file:
| inputlookup filename.csv
| rex field=_raw "address: (?<Server>.*)"
It is not returning the "Server" field with any data. Is this because it is a csv file instead of a text file? What am I missing because I'm not getting any errors from Splunk.