I can't seem to get my regex to work as a field extraction. below is an example string and the regex I'm trying to use.
This is what I've been trying in Splunk:
rex field=url "(?<=ab&q=)\S*(?=&oq)(?
Basically I want to extract everything between "ab&q=" and "&oq"