Hi, I have the below string and I'm trying to extract out the downstream status code by using this expression. I used to do this a long time ago but it appears those brain cells have aged out. Regex that works in regex 101 but not Splunk rex "DownstreamStatus..(?<dscode>\d+)"|stats count by dscode String {"ClientAddr":"blah","ClientHost":"blah","ClientPort":"50721","ClientUsername":"-","DownstreamContentSize":11,"DownstreamStatus":502,"Duration":179590376953,"OriginContentSize":11,"OriginDuration":179590108721,"OriginStatus":502,"Overhead":268232,
... View more