Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Regex pattern for "Add Data" / custom sourcetype

$
0
0
Hello guys, please let me know the regex pattern format for this screen : /en-US/manager/search/adddata/datapreview Is it raw regex pattern like /^(\S+) \S+ \S+ \[([^\]]+)\] "([A-Z]+)[^"]*" \d+ \d+ "[^"]*" "([^"]*)"$/m or something like ^(?P[^ ]+) with the field name? Many thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>