(<whatever_name_you_want>[0-9]+)
With the above, ([0-9]+), you are matching a number between 0-9, 1 or more times, but are not naming that anything, so its not letting you save that thing (because Splunk would do nothing with that matching).
Anything outside of the parenthesis is outside of the capture, the first thing in the paren should be
<fieldname>
then the pattern you want to extract, then close paren, then anything after that pattern that further restricts the match.
Regex can be tricky at first, and certainly Splunk has its own regex quirks, but it gets easier - we promise 🙂
... View more