Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Inline REX extraction not working once I move it Field Extraction

$
0
0

The following gives me exactly what I want

host=****** Failed_Reason minutesago=15 | rex "\>(?<Failed_Reason>.*?)\<"

but when I use the regex to build a field extraction I cannot get a result even after restarting the indexer. The search output is the same.

The field extraction format is

"\>(?<Failed_Reason>.*?)\<"

Any idea why this is not working?

Thanks


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>