I want to track multiple ORA numbers, we received different format logs as below, can you help me to write a query for this.
Logs/Events:
2022-08-04T06 : 55 : 54.009110 + 01 : 00 opiodr aborting process unknown ospid ( 8696 ) as a result of ORA - 609
2022-08-04T06 : 51 : 54.137474 + 01 : 00 WARNING : inbound connection timed out ( ORA - 3136 )
Hello @jackin ,
You can write the below query to your base search to extract the ORA field.
| <your_base_query>
| rex field=_raw "(ORA - )(?P<ORA>\d+)"
---
If you find this answer helpful, an upvote is appreciated..!!