Splunk Search

Unable to view the field created using rex

prabu_harsh12
New Member

string used in the search rex "(?i) Message= (?P[^.]+)"

Event log form where im trying to extract "Message=The Windows Management Instrumentation service entered the running state"

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Be careful of extra spaces in your rex string. Also, the '(?i)' is unnecessary.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

neelamssantosh
Contributor

For better/future reference,
Use Interactive Field Extractor
http://www.splunk.com/view/SP-CAAADUY

Splunk, makes life's easy :).

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Be careful of extra spaces in your rex string. Also, the '(?i)' is unnecessary.

---
If this reply helps you, Karma would be appreciated.

prabu_harsh12
New Member

It worked after removing the extra space. thanks so much! Wish you a happy new year!

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...