Hi everybody
I wanted to extract all hostname from this field "local_address" and save in a new field call "host" so that i only get the hostnames after "@"
I believe we can do it by "search | spath | rex field=local_address "@(?P[^-]+)"| stats count by _time host"
please corerct this.
below is the exact field
local_address
14081300@abc3-def-ghi1101.jklm.opqr.com
13546330@wer2-gre-oug1201.jklm.opqr.com
thanks
Hi,
You can try below search
<yourBaseSearch>
| spath
| rex field=local_address "\@(?<ext_host>[^\h]*)"
| stats count by ext_host,_time
Hi,
You can try below search
<yourBaseSearch>
| spath
| rex field=local_address "\@(?<ext_host>[^\h]*)"
| stats count by ext_host,_time
If local_address
is multi-valued field then you can try below query
<yourBaseSearch>
| spath
| rex field=local_address "\@(?<ext_host>[^\v]*)" max_match=0
| mvexpand ext_host