In addition to $1 $2 $3..., does it support (?<namedField>...)?
http://docs.splunk.com/Documentation/Splunk/6.3.1/Admin/Transformsconf
Yes, you can, like this:
[SomeArbitraryNameHere]
SOURCE_KEY=YourSourceFieldName
REGEX=Your RegEx with (?<NamedCapture>.*) Here
You need a props.conf
reference to SomeArbitraryNameHere
to trigger it.
Yes, you can, like this:
[SomeArbitraryNameHere]
SOURCE_KEY=YourSourceFieldName
REGEX=Your RegEx with (?<NamedCapture>.*) Here
You need a props.conf
reference to SomeArbitraryNameHere
to trigger it.
thx it worked
Use $n (such as $1, $2, and so on) to specify regex match outputs. Default is ::$1
Is the default in the Field Transformation GUI suppressed by default?
The way I read this paragraph, groups can only be referred to by number.
When you create concatenated fields with FORMAT, "$" is the only special
character. It is treated as a prefix for regex-capturing groups only if
it is followed by a number and only if the number applies to an existing
capturing group.