Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

why does a ".*" extraction line ruin my query?

$
0
0
Here is my original query: tag=autoexpress_prod level=debug mdc.InvocationName=calculatePremiumAutoProcessc "serviceRequestName" | rex field=message "\(?\w+)" | rex field=message "\(?\w+)" | rex field=message "\(?\w+)" | dedup Married Fname Lname mdc.QuoteID | join mdc.QuoteID [search tag=autoexpress_prod level=debug mdc.InvocationName=recordBillingAccount "webservice request XML" | rex field=message "\(?.{0,12})"] | rename mdc.State as State, mdc.QuoteID as QuoteID | table _time, PolicyNumber, State, QuoteID, Fname, Lname, Married | sort 0 Fname Lname | streamstats count by Fname Lname QuoteID | eventstats max(count) as keep by Fname Lname | search keep=2 it looks for people that change their marital status. The problem arises when I add this line: | rex field=message"<DECFirstName>(?<Message>.*)</DECFirstName>" it completely prevents the query from grabbing certain pieces of data and I have no idea why?

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>