Need help with regex...should start with " end with space or ?
Need entire string in a field starting with " and end until j.prod or c.cat etc...
"GET /brit-pocket09fress/cprod121000019___/j.prod HTTP/1.1"
"GET /nprod789jkj908989heys__/j.prod?icid=&searchType=
"GET /Zin-carsposn-vwlvet-09878__/c.cat HTTP/1.1"
Try this
your base search |rex field=yourfield "\"(?<SomefieldName>\S+\s+[^\s\?]+)"
Like this:
(?<myCapture>"[^\s]+\s+[^\s?]+)(?<=\/)
some how it's giving me the date when i do | rex field=_raw (?"[^\s]+\s+[^\s?]+)(?<=\/) | table myCapture, _raw
Try this
your base search |rex field=yourfield "\"(?<SomefieldName>\S+\s+[^\s\?]+)"