Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How would I configure my regex to also include Windows data?

$
0
0
I have a query that will identify all the logs in my instance for a certain index, it list everything running except for Windows. What am i missing? thanks in advance. index="source" | rex field=source "^.*\/(?=[^/])(?.*?)($|\s|\-|\_)"

Viewing all articles
Browse latest Browse all 47296

Trending Articles