I have this query in Splunk which works in a dashboard that I created:
source="xyz" oneCertainString error| rex field=_raw "error....code.:-(?&