I am trying to use a similar splunk query: index="myIndex" appname="myapp" msg.result.message ="*TradingSymbol(s):*"
| rex "(?<=TradingSymbol\(s\): )[\w-]+(?:, [\w-]+)*," | stats count BY TradingSymbol(s), Elapsed I wanted to get them in a table as Date, PortfolioSymbol(s), ElapsedTime When I try to run it, I get the error Error in 'rex' command: The regex '(?<=TradingSymbol\(s\): )[\w-]+(?:, [\w-]+)*,' does not extract anything. It should specify at least one named group. Format: (?<name>...). When I try the same in regexr.com, for the below output, (?<=TradingSymbol\(s\): )[\w-]+(?:, [\w-]+)*, able to highlight 2AC5, 3DE2, 5CE3, 4FA4, 1BM5, TEST-2AB6, TEST-2BA9,
RefreshAsyncjronized End, TradingSymbol(s): 2AC5, 3DE2, 5CE3, 4FA4, 1BM5, TEST-2AB6, TEST-2BA9, ElapsedTime: 12.3762658
Please help, Thanks
... View more