Hi ,Could anyone assist I am attempting to perform a query that extracts an event in splunk
"fd-credit-darc-quotations--gb-hbeu" which is part of a longer string below/
<14>1 2018-07-24T18:34:42.81641+00:00 **whjc100-digital-fet-platform-prd.prod.fd-credit-darc-quotations--gb-hbeu**-1-0-1-20180626161234pred.prd.
I tried using below but it extracts everything starting from fd-credit card but does not stop at --gb-hbeu =>
| rex field=_raw "whjc100-digital-fet-platform-prd.prod.(?.[a-zA-Z0-9]{4}$)"
Could anyone help,Thanks
@HenryFitzerald Rather than pile on to a three-year-old question with an accepted answer, you should ask a new question describing your problem. I did it for you this time. 😉
Thanks RichGalloway,much appreciated