This should do it
If you need to put in the rex command, you could use
Otherwise the quotation marks may confuse the search parser.
Note that the resulting field is named
Okay, the original question said that you wanted a regex that would extract a value. In Splunk terms, you are asking for a field: a field is defined by a regex and has a value based on what is extracted from the events. A regex that defines a field could be used with the
rex command, or it could be used with the interactive field extractor.
If what you want is a search, then you need to edit your question. What exactly do you want to accomplish? I am not sure now that you need to use a regular expression at all.
this search query returns 0 items
sourcetype="worker-stderr-*" op-failed | regex _raw=\'text:\'\s*\"(?<errorText>.*?)\"
this search query returns 10 items
is this what you had in mind or am I missing something.