Hi, I have a daily search that suddenly stopped working (upgraded from 6.7 to 7.1 before it stopped working, I believe):
|inputlookup my_file.csv
|eval shared_sources="master_source"
|append
[search sourcetype="my_sourcetype"
|fields someIPs host
|dedup someIPs
|rex field=host mode=sed "s/\..*$//"
|rename someIPs as ip
|rename host as host_my_sourcetype
|eval shared_sources="my_sourcetype"]
What's the issue with my rex command?
Upgrade to the latest maintenance release; there is nothing wrong with your rex.
Just verified that the version we're using is 7.1.7. Is there any indication on what maintenance release we currently have in the Splunk version?
Does the sub-search work if you run it by itself or do you get the same error?
@oscar84x I still get the same error
could you provide sample test values for the host?
@mayurr98 Sure, they're all in this format: GHRCEDC4BA.ghij.def.abc