This seems like a straight forward config can someone spot where it's going wrong. I am unable to extract the "aaa" field. The regex and extraction works correctly with the following search.
sourcetype=alerts | rex field=_raw "(?<aaa>.*\d{4}),"
Raw data (sourcetype alerts):
Wed Nov 21 09:47:41 EST 2012,CAM,Outer Door,Door State,Closed
Props.conf(/opt/splunk/etc/apps/myapp/local/):
[alerts]
KV_MODE=none
EXTRACT-door = (?<aaa>.*\d{4}),
Search:
sourcetype=alerts | extract reload=true
Thanks,
Thomas