Reporting

Data model calculated field with max_match

tomaszwrona
Explorer

Hello,

i would like to create a calculated field within a data model with following expression:
rex field=_raw (?.*) max_match=0

But how to tell the data model to consider the max_match expression, as it cannot be used in a calculated field?
I have already tried to edit the data model file, replacing 'mutlivalue':'false' with 'mutlivalue':'true' but after that it was still single value field.

Best regards
Tomasz

0 Karma
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...