Hi Team
Getting this error message frequently in internal logs of Splunk.
Error in 'where' command: The expression is malformed. An unexpected character is reached at '*) OR match(indicator, *_ip) OR match(indicator, *_host))
Any hints will be appreciated.
Thanks in advance
The match function expects a regex string as the second parameter. In regex "*" is a modifier meaning zero or more of the previous match item. If "*" appears at the beginning of the regex expression, there is no previous match item, hence the error.