Dear all,
I want to exact server version from the event, what i want is to extract 1.7.2, but my command can't show anything, could you pls kindly help?
event:
action="INFO:AppLoader (1.7.2 @143650)" category="System" label="(3a4c5025d457ef2e)" table="****"
AppLoader |rex field=_raw "action=\"(.:AppLoader (?<version> @.))" |stats latest(version) by table
The problem is probably the " after action= you need to either to escape that by putting a \ in front of it or remove it at all. You can use the below search to test.
AppLoader |rex field=_raw "action=.*?\((?<version>[^\s\@]+)" |stats latest(version) by table
The problem is probably the " after action= you need to either to escape that by putting a \ in front of it or remove it at all. You can use the below search to test.
AppLoader |rex field=_raw "action=.*?\((?<version>[^\s\@]+)" |stats latest(version) by table
The last line is my current command