Stream alert regex help


Hello. I’ve created an extractor for one of my fields however when trying to search for terms within that field my searches are failing.

I can search for my extractor field named ‘fv_response’ like this and I can see the messages fine:

fv_response:"INFO - Response: {\"success\":false",\"errorCode\":2,\"message\":\"Invalid"

However when I try to search for just up to the word false I get no results. I’ve tried

fv_response:"INFO - Response: {\"success\":false."
fv_response:"INFO - Response: {\"success\":false.*"
fv_response:"INFO - Response: {\"success\":false.+*"

What is the correct syntax for searching for anything after the word false? Thank you.

(Jan Doberstein) #2

please refer to the streams documentation.


I have, and that documentation doesnt help me. Can you provide examples please?

(system) closed #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.