hi,
I'm trying to prepare output at the index time for IIS logs and cs_username which for now contains prefix that I DO NOT want.
cs_username = "0#.w|domain\username"
I want to have that field witouth prefix
cs_username = "domain\username"
Sometimes this cs_username value that is correct "domain\username"
How I move this
|rex field=cs_username "(0#.w|(?.)|(?.))"
to work in transforms.conf and at best to extract value in same field (just overvrite cs_username)
or at least to the same like is in example user1 and user2
correction... working version is: |rex field=cs_username "(0#.w|(?<\user1>.)|(?<\user2>.))"