Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

can you help me on regex please

$
0
0
hi I want to add a rex field in my search index=windows sourcetype="wineventlog:system" SourceName="Disk" count="$process$" | dedup _time | table _time host Type EventCode There is 2 conditions for my rex field : Une erreur a été détectée sur le périphérique \Device\Harddisk1\DR1 lors d'une opération de pagination. \Harddisk\ has to fnish by 0 or 1 but not by another number After \Harddisk0\ or \Harddisk1\ its mandatory to have DR could you help me please??

Viewing all articles
Browse latest Browse all 47296

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>