Hi, I have a daily search that suddenly stopped working (upgraded from 6.7 to 7.1 before it stopped working, I believe):
|inputlookup my_file.csv
|eval shared_sources="master_source"
|append
[search sourcetype="my_sourcetype"
|fields someIPs host
|dedup someIPs
|rex field=host mode=sed "s/\..*$//"
|rename someIPs as ip
|rename host as host_my_sourcetype
|eval shared_sources="my_sourcetype"]
What's the issue with my rex command?
Upgrade to the latest maintenance release; there is nothing wrong with your rex
.
Just verified that the version we're using is 7.1.7. Is there any indication on what maintenance release we currently have in the Splunk version?
Does the sub-search work if you run it by itself or do you get the same error?
@oscar84x I still get the same error
could you provide sample test values for the host?
@mayurr98 Sure, they're all in this format: GHRCEDC4BA.ghij.def.abc