I have a basic rex question:
In my splunk query I have:
| eval foo = ....
and I would like to be able to apply rex on foo
but I don't seem to able to do so?
Does anybody know how to apply splunk regex on a variable defined in a query, such a foo above?
| rex field=<field> "<regex>"