index=test host=rider2*58* APP=TEST | rex field=_raw "*CAR:(?\d+)*" | table CAR
this is my query. But whenever i run it, i get empty values in table CAR. Can someone please help me how can i get the values populated ? everything else works fine but values are not getting displayed
I think the problem is in the regex. can you give us sample events and let us know what do you want to extract.
Please check with the Regex you wrote & there can be chances of failure in the earlier query as well.
Like check if index=test host=rider2*58* APP=TEST is populating any events.
& it would be helpfull, if you provide us a sample event which contains all the field values.
Thanks