I want to extract the Country and the Node. When I use the rex in regex101, it works fine. But when I put it on Splunk search, it did not extract the Country and the Node. Do you guys know where is my mistake?
This is my search query.
index="maxis_csaroam_index" source="/home/csaops/csaroam/*_MOS.csv"
| dedup Description
| table Description
| rex field=Description "(?<Country>[\w]+)(?<Node>[\w\- ]*\n)"
Try without the newline in the match
| rex field=Description "(?<Country>[\w]+)(?<Node>[\w\- ]+)"
Give this a try (avoided using dedup command as well, best practice)
index="maxis_csaroam_index" source="/home/csaops/csaroam/*_MOS.csv"
| stats count by Description
| table Description
| rex field=Description "(?<Country>\S+)\s+(?<Node>\S+)"
Try without the newline in the match
| rex field=Description "(?<Country>[\w]+)(?<Node>[\w\- ]+)"