I have a field in splunk named commandline. I want to filter this field just by values containing "C:\"
This appears sometimes at the beginning of the filed value and other times in the middle. Can someone help me with a regex statement or other search filter to narrow my results this way?
Use wildcards
commandline=“*C:\*”
Hi @nwalker15 ,
provide sample logs and highlight the keyword which you want to extract.
Use wildcards
commandline=“*C:\*”