Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

within "Extract Fields", how can I start the regular expression with a value from another field?

$
0
0
I have a field 'foo', it has a value like "data1_data2" I'd like to make an Extracted Field that starts with the contents of 'foo', instead of the entire raw event is that possible?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>