We recently upgraded our Splunk version from 6.5 to 7.0.3 and this then caused some rex queries in dashboards to stop working. Anyone able to advise why this would cease to work and how it could be resolved?
Query being run is:
| rex field=_raw "^\"(?<TimeStamp>[^,]+)\",\"(?<Realmname>[^,]+)\",\"(?<Latency>\d+)\""
Please provide some sample data of what is no longer working.
Thanks!
an example of sample data from log would be:
Oct-22-2018 17:05:34.153: ### Thread alive 1540224334153
"Oct-22-2018 17:05:35.470","bs1_uat_trd_x2n1","1","1540224335470","1540224335469","1540224335450"
Oct-22-2018 17:05:44.154: ### Thread alive 1540224344154
"Oct-22-2018 17:05:45.470","bs1_uat_trd_x2n1","1","1540224345470","1540224345469","1540224345470"