The regular expression is correct according to RegExr, but i keep on getting this error
Error in 'rex' command: Encountered the following error while compiling the regex 'count(domain)=(?<count(domain)>.*)': Regex: syntax error in subpattern name (missing terminator)
Here is what i have in Splunk Search:
rex field=_raw "count(domain)=(?<count(domain)>.*)"
Thanks guys
hi
try this search code :
...................................|rex field=_raw "count\(domain\)\=(?<count_domain>[^\,]+)"|table count_domain
Try this (run anywhere)
index="AAAA" source="BBBB" | rex field=_raw "count\(domain\)=(?<domain_count>.*)," | rename domain_count as count(domain)
Thanks for your help
^^
sample log
05/20/2014 00:00:00 +0900, search_name=AAAAA, search_now=1400606400.000, info_min_time=1400511600.000, info_max_time=1400598000.000, info_search_time=1400606401.123, count(domain)=744788, date_wday=tuesday
Thanks
Hi ilove275,
brackets inside the rex field name cause the syntax issue.changing the field name count(domain) to domain_count would help u solving the issue.
rex field=_raw "count\(domain\)=(?<domain_count>.*)"
Thanks.
it doesn't come out the File name "domain_count" when I use "Rename" commamd
field name's "count(domain)" not "domain_count"
My Splunk Search
index="AAAA" source="BBBB" | rex field=_raw "count(domain)=(?
error
Error in 'rex' command: Encountered the following error while compiling the regex 'count(domain)=(?
Thanks rakesh_498115
and don't forget to append a "
at the end of the regex command
can you provide some sample events please?