I am new to splunk and regex, sorry for poor knowledge.
I am trying to extract hostname from
So far I came up with [a-zA-Z]*([^]+).log$ but this result has _messages.log.
How Can I get rid of this part?
Assuming that 'hostname' only contains alpha-numeric characters.
Or, if your 'hostname' doesn't include underscores:
You need to 'escape' the period character, as it has a special meaning in regex.