Your example is not valid, please avoid the confusion between :
that would look like :
mysearch repid | regex _raw="repid=\d+"
or if the field is already extracted
mysearch repid | regex repid="\d+"
mysearch repid | rex "repid=(?<REP_ID>\d+)"
here is a complex way to do it, but not really worth it
mysearch repid | rex "repid=(?<REP_ID>\d+)" | fillnull REP_ID value="was not found" | where REP_ID!="was not found"
Your example is not valid, please avoid the confusion between :
that would look like :
mysearch repid | regex _raw="repid=\d+"
or if the field is already extracted
mysearch repid | regex repid="\d+"
mysearch repid | rex "repid=(?<REP_ID>\d+)"
here is a complex way to do it, but not really worth it
mysearch repid | rex "repid=(?<REP_ID>\d+)" | fillnull REP_ID value="was not found" | where REP_ID!="was not found"
got that to by using (?i) in regex _raw="(?i)repid=\d+"
awesome! thanks for the help. is it possible to make the repid in regex _raw="repid=\d+" case insensitive? the reason is that there might be some cases of RepID or repiD, etc.