I would like to see instances with the source 'test*' - that is everything that starts with 'test' but eliminate 'testn' occurrences. I am fine with everything else so 'test1', 'test2' are okay but not 'testn1' and not 'testn2'. Do I need regex or is there another way of doing this?
| rex "(?m)(?<test>test[^n].*)$"
I have used $ to show where the string ends but you may have a more appropriate string to use from your events
What if 'test' is part of a field?
| rex field=fieldname "(?m)(?<test>test[^n].*)$"