Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Props.conf extractions

$
0
0
Any reason why my statement for props.conf isn't showing up as an extracted field? EXTRACT-kls_error = (?(kls_error_*)\w+) When I use just the rex in a search it gets the exact info that I need but when I am trying to create an extracted field it cannot

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>