Hi Splunk_God,
take a look at this macro which ships in Splunk 6.2:
[audit_rexsearch]
definition = rex "search='(?<search>.*?)', autojoin"
it uses "
instead of your '
so changing the macro to
[Testing]
definition=rex field=file "(?P\.(.{2,4})$)"
should do the trick.
Hope this helps ...
cheers, MuS
Hi Splunk_God,
take a look at this macro which ships in Splunk 6.2:
[audit_rexsearch]
definition = rex "search='(?<search>.*?)', autojoin"
it uses "
instead of your '
so changing the macro to
[Testing]
definition=rex field=file "(?P\.(.{2,4})$)"
should do the trick.
Hope this helps ...
cheers, MuS