Hi Everyone,
I have below sets of raw logs:
source-timestamp=1655611288414,event-type:Lead_Staging__c
source-timestamp=1655611288414,event-type:Account_Snapshot__c
source-timestamp=1655611288414,event-type:Opp
I want to fetch all the event -type.
Can someone guide me.
The previous rex worked with the examples you gave - because these examples were incomplete w.r.t. your actual events, it didn't work for your real event.
Assuming that the new examples are an accurate representation of your real events, try this
| rex "event-type:(?<eventType>[^,]+)"
| rex "event-type:(?<eventType>.+)"
Hi @ITWhisperer
Its not showing the correct way.
My entire query is this
index=abc ns=blazepsfpublish app_name=pulldataoneforce* "The Total Process Time to publish in Kafka topic is" | rex "event-type:(?<eventType>.+)"| rename eventType as event-type|eval Date=strftime(_time, "%Y-%m-%d") | timechart span=1d count(source_uniqueid) as "The Total Process Time to publish in Kafka topic is" by event-type
I have attached the screenshot to show how it is coming
These are my raw logs
source-uniqueid=cdc3bcb5-9ad4-46a9-92dc-4c84b081ab3b, source-timestamp=1655646610318,event-type:Lead_Staging__c, source-type:OneForce, memsql-persist:true, channel:/event/tel_External_Change_Event__e, replayId:14522702, The Total Process Time to publish in Kafka topic is (milli-sec)=7
Can you please guide
The previous rex worked with the examples you gave - because these examples were incomplete w.r.t. your actual events, it didn't work for your real event.
Assuming that the new examples are an accurate representation of your real events, try this
| rex "event-type:(?<eventType>[^,]+)"