Set up an alert with the search command:
source="C:\test\data\log1.txt" | rex v="(?
the alert has never been triggered, although the same search on Aplunk UI generates results.
You should have tried by black slash
So don't use double quotes with rax command in scheduled searches for alerts. Just use a search like:
source="C:\test\data\log1.txt" | rex v=(?
This works fine for alerts and is more readable.
" works fine on windows.