Hello Splunk Wizards, I know there are plenty of people who've had similar issues, but I haven't been able to use their resolution for my issue. I'm doing a search time field extraction to capture login username, which includes a backslash. I have the regex correct (?P<User_Name>(domain\\\\\\S+)) slightly modified from regex 101 for Splunk. In the field extraction wizard, it perfectly grabs all sample data (ex: domain\username). (?P<User_Name>(domain\\\\\\S+)) However, this field doesn't show up in search when looking at the exact same sample data. I've performed a verbose search and made sure all available fields are showing, it's not there. I've tried using groups names I know Splunk isn't already using, no improvement. Pretty sure it was to do with the backslash, because if I modify the regex to (?P<User_Name>domain\S+), the field extraction shows up in search, but it also contains data that isn't exactly correct. (?P<User_Name>domain\S+) I've tried variations with more and less backslashes, none seem to work. I guess I can live with a sloppy field extraction if that's all I can do, but the first regex really is perfect. Any ideas?
... View more