Hi
I was trying to go thru Splunk Tutorial, but now I am having trouble in getting sampledata.zip indexed using the host regex shown in the Splunk Tutorial page. My Splunk is on Windows.
Sampledata.zip:./([^/]+)/
http://docs.splunk.com/Documentation/Splunk/latest/User/Adddatatutorial
Is this regex good for Windows Splunk?
Thanks,
In 4.3.2, I confirmed this is working for both type of OS.
** The regex in Tutorial Doc is not working, be careful.
In 4.3.2, I confirmed this is working for both type of OS.
** The regex in Tutorial Doc is not working, be careful.
No as path where it will be extracted will be \
rather than /
then try :
Sampledata\.zip:.\\([^\\]+)\\
Well, the regex in tutorial is not working.
I saw regex for windows in tutorial, thank you!