Thanks for the help. I am really new to this. So i went back to SPLUNK>Extract and put what you have given me into the "Generated pattern (regex)" where i can EDIT it .. and I now have this:
(?i) A .(?P [^s]+)$
fieldname = your dc_name
When i APPLY this, or TEST it, it shows me my data, and hightlights the matches , but only shows me highlighted domain names but not all of them in the data set.
Sorry i dont know much about this. First time. Do you think i am good??????? Looks good.
And. Thank you very very much
... View more