Trying to extract a string into a new field. A sample of log is as follows:
productName = Special Day Argyle Socks for Men (Special Day Argyle Socks Size 10-13)
| rex "productName\s=\s(?<ProductName>\s[\w\W]+)"
Not sure where to go from here. When I test within regex101, it works just fine. But when I move to Splunk i get nothing.
Update
Added this but now it doesn't stop at a new line
| rex "productName\s=\s(?<ProductName>[\w\W]+\n)"
Figured it out
| rex "productName\s=\s(?<ProductName>.*)"
I've changed your comment to an answer. Please accept your answer so that it can be noted as having been answered to your satisfaction. You should earn a badge for doing so as a result. 🙂
Cheers, Thanks!