hey guys did someone ever happed to come through this problem. I'm using Splunk Cloud I'm trying to extract a new field using regex but the data are under the source filed
| rex field=source "Snowflake\/(?<folder>[^\/]+)"
this is the regex I'm using when i use it in the search it works perfect. but the main goal is to save this search as a permanent field. i know that the the field extraction draw from the "_raw" there is an option to direct the Cloud to pull from the source and save it a permanent field.
... View more