Im looking to achieve the following using Rex.
Below is the search query which im trying to run
sourcetype=XXXXXX (-1XXXXX OR -1XXXXX) | rex "access-list\s+(?
I know that i can store these results in two different variables.
But i want to combine them into a single rex and store the output of these two rex into a single variable "Access" itself.
Please let me know on how to achieve this functionality?
Please share your thoughts on this.
You can combine the two regular expressions by OR'ing the prefixes using the pipe symbol: access-lists+|access-groups+
Tried the following and i dont see the "access" variable getting generated by the regex
sourcetype=XXXXXX (-1XXXXX OR -1XXXXX) | rex "(access-list|access-group)\s"?(?
Im getting an splunk error "Unknown search command 'a'."