Hi,
PACKET 000000000D9982E0 UDP Rcv 10.164.45.152 ef37 Q [0001 D NOERROR] A (12)orzdwjtvmein(2)in(0)
This is my field,
I want to tabulate to create a table from this. output should be something like:
from to
10.164.45.152 (12)orzdwjtvmein(2)in(0)
Thanks.
Hi
Give a try
| makeresults |eval msg="PACKET 000000000D9982E0 UDP Rcv 10.164.45.152 ef37 Q [0001 D NOERROR] A (12)orzdwjtvmein(2)in(0)"
| rex field=msg "(?P<temp1>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
| rex field=msg "(?P<temp2>[(].+)"
| eval result = temp1." ".temp2 |table result