Set up an alert with the search command:
source="C:\test\data\log1.txt" | rex v="(?
the alert has never been triggered, although the same search on Aplunk UI generates results.
You should have tried by black slash \"(?.*)\"
So don't use double quotes with rax command in scheduled searches for alerts. Just use a search like:
source="C:\test\data\log1.txt" | rex v=(?
This works fine for alerts and is more readable.
" works fine on windows.