Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why am I unable to extract this field with my current rex statement?

$
0
0
I have a regex that should be extracting the **employeeType** field from an event. Below is the text of the event and the regex I am using. Details: Attributes: employeeType Contractor Search: mysearch | rex "employeeType\n\t\t\t(?\w+)" We see the extraction work on regxr, but it doesn't seem to extract in the search.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>