Splunk Search

Unable to view the field created using rex

prabu_harsh12
New Member

string used in the search rex "(?i) Message= (?P[^.]+)"

Event log form where im trying to extract "Message=The Windows Management Instrumentation service entered the running state"

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Be careful of extra spaces in your rex string. Also, the '(?i)' is unnecessary.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

neelamssantosh
Contributor

For better/future reference,
Use Interactive Field Extractor
http://www.splunk.com/view/SP-CAAADUY

Splunk, makes life's easy :).

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Be careful of extra spaces in your rex string. Also, the '(?i)' is unnecessary.

---
If this reply helps you, Karma would be appreciated.

prabu_harsh12
New Member

It worked after removing the extra space. thanks so much! Wish you a happy new year!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...