Hi everyone.
I'm new for splunk. I'm learning splunk using splunk's documents in website.
Now I'm learn to splunk scenario lesson of how to extract, when I try to extract fields called username, clientip. But the data has different pattern.
How can I write regex for this pattern?
attached is my extract fields.
Sorry for my english 🙂
This regex string should extract the user name or "invalid user x".
"for (?P<username>[\w ]+) from (?P<clientip>[^ ]+)"