Using rex and it seems as if Splunk sees the open square bracket as the beginning of a subsearch. Have I written this wrong or is there a workaround
| rex \w+\.\w+\.\w+[a-z]\_(?<Facility>[[:alnum:]]+)
Hi there,
Missing quotes perhaps, | rex "\w+\.\w+\.\w+[a-z]\_(?<Facility>[[:alnum:]]+)"
Hi there,
Missing quotes perhaps, | rex "\w+\.\w+\.\w+[a-z]\_(?<Facility>[[:alnum:]]+)"
Yep, worked, I feel a bit silly.
Glad it worked. It happens all the time!!