Hi All,
I am trying to use below regex in my splunk SPL, which is working fin in rubular but not working as SPL.
|rex field=_raw (?<Severity?\s\w{7,8}\;) not working
Please suggest
Shouldn't the expression include ">" after Severity?
(?<Severity>\s\w{7,8}\;)
Although this would include the space, followed by 7 or 8 letters/numbers and a semi-colon in the extracted field. Perhaps this might work better
"\s(?<Severity>\w{7,8})\;"
Shouldn't the expression include ">" after Severity?
(?<Severity>\s\w{7,8}\;)
Although this would include the space, followed by 7 or 8 letters/numbers and a semi-colon in the extracted field. Perhaps this might work better
"\s(?<Severity>\w{7,8})\;"
Hi @vijaya5,
without a sample of your logs it's realy difficoult to try to help you!
Anyway, probably the problem is that quotes on the border of the regex are missing in the rex command.
Please, use Code sample for your regex.
Ciao.
Giuseppe