Hi my Name is JaeHyun, Cho
I lives in korea.
my question is why splunk not allow multi charactor fields?
some clients complained about that!
they want to use a Multi charator fields likes "782222-INP"
do you have a plan ????
sorry about my pure english
thank you
Splunk doesn't support special characters other than underscore ("_") in the field names. You can replace your hypher ("-") with that. Other than that the format your specify does work. See this run-anywhere example.
|stats count | eval message="This is field Extraction Test" | table message | rex field=message "^(?<782222_INP>[^\s]+)" | rex field=message "^([^\s]+\s){1}(?<78222dfd____2_INP>[^\s]+)" | rex field=message "^([^\s]+\s){2}(?<INP_782222_>[^\s]+)"| rex field=message "^([^\s]+\s){3}(?<12_782222_INP>[^\s]+)" | rex field=message "^([^\s]+\s){4}(?<AbCd_782222_INP>[^\s]+)"
Splunk doesn't support special characters other than underscore ("_") in the field names. You can replace your hypher ("-") with that. Other than that the format your specify does work. See this run-anywhere example.
|stats count | eval message="This is field Extraction Test" | table message | rex field=message "^(?<782222_INP>[^\s]+)" | rex field=message "^([^\s]+\s){1}(?<78222dfd____2_INP>[^\s]+)" | rex field=message "^([^\s]+\s){2}(?<INP_782222_>[^\s]+)"| rex field=message "^([^\s]+\s){3}(?<12_782222_INP>[^\s]+)" | rex field=message "^([^\s]+\s){4}(?<AbCd_782222_INP>[^\s]+)"