I have 2 types of Messages in my log
for 1st i want to split it from ":" deliminator
and for 2nd i want deliminator to be "for"
my base query is something like belwo :
.... Message1 OR Message2|eval delim=(if Message1, deliminator should be ":" ,if Message2 ,deliminator should be "for"| eval num=split(Message,"delim")|eval field=mvindex(num,0)|stats count by field
Please help me on this .
How about you try this and take whichever one you are interested in out of
sufFix fields if your initial string is in field
your query to return events | rex field=Message "^(?<preFix>^.*?)(\s:\s|\sfor\s)(?<sufFix>.*)" | table preFix, sufFix, Message
Its not working 😞 , its only showing the last
Message are like :
Application photobuf message : dhfksdhkfhksdhfk hdfkshfskhfk dfhkshdfkshfhs
Application Data loaded successfully for Photo No - 123456789 ; OrderIPlaceno - 987654321
using | rex "(:|for)\s(?.)" is giving Photo No -1234
|stats count|eval _raw="Application photobuf message : dhfksdhkfhksdhfk hdfkshfskhfk dfhkshdfkshfhs"|append [|stats count|eval _raw="Application Data loaded successfully for Photo No - 123456789 ; OrderIPlaceno - 987654321"]| eval delim = if(like(_raw,"%:%"),":","for")|eval _raw=split(_raw,delim)|eval split1=mvindex(_raw,0)|eval split2=mvindex(_raw,1)
Field name is Message.From Message1 and 2 i means to say different type of message.
So there are basically 2 types of Messages in field Message
1st Applicatio photobuf message : dfgjsdgfjsgd gsdkgfksdgf ksdgfksdgfk s--- for such message i want ":" as delim
2nd Application2:Photoinserted to somesets for an Account--- for these messages i want "for" as delim