I'm trying to use a regular expression to grab words out of a logfile that begin with "FNR" and are exactly 10 alphanumeric characters long, and save that to a new field called ErrorCode.
The expression I've written in a PCRE generator doesn't seem to work with Splunk. It's below:
(^|)FNR.......(|$)(?P)
How do I make it work with Splunk?
Is that 10 characters including "FNR" or after?
Try this regex (?<ErrorCode>FNR\w{7})
.
BTW, www.regex101.com seems to do a good job of validating regular expressions Splunk will handle.
Is that 10 characters including "FNR" or after?
Try this regex (?<ErrorCode>FNR\w{7})
.
BTW, www.regex101.com seems to do a good job of validating regular expressions Splunk will handle.
Works perfectly. thank you my friend