I have files that have names like this:
appflow-0017c569f354.syslog-dynamic-96
appflow-0017c569f354.syslog-dynamic-97
appflow-0017c569f354.syslog-dynamic-102
...
I tried the following regex:
appflow-+[0-9a-z]{12}+.syslog-dynamic-+[0-9]{1,6}
but splunk was not indexing any of the files. What is the correct regex?
I would suggest;
appflow-[a-z0-9]{12}\.syslog-dynamic-\d+
which is probably precise enough.
/K
Hi,
Also an idea:
appflow-[^\.]+\.syslog-dynamic-\d+
-- Jens
I would suggest;
appflow-[a-z0-9]{12}\.syslog-dynamic-\d+
which is probably precise enough.
/K
Thanks for the speedy response.