index=system* sourcetype=inventory order=829
I am trying to extract the 3 digit field number in this search with rex to search all entries with only the three digit code. I tried:
index=system* sourcetype=inventory (rex field=order "\d+")
index=system* sourcetype=inventory (rex field=order "(\d+)")
index=system* sourcetype=inventory (rex field=order "[0-9]{3}")
What is the correct way to do this?
Thanks!
↧