Trying to build a parser, but facing the below issue.
I extracted two fields from my logs: action_failed and action_success
Later, I gave them a field alias as below:
action_failed as action1
action_success as action1
linked them to a lookup:
mylookup action1 OUTPUT action
The issue is that only one field is parsed, and that is the first one in my case action_failed, the other field is not picked. Is there any solution for this?
You are probably using the same class names in the field alias
if you use FIELDALIAS-action = on both only one will work.
try something like this:
FIELDALIAS-failed_action = action_failed as action1
FIELDALIAS-success_action = action_success as action1
try to not use field alias . If you extract both fields (action_failed,action_success) manuelly you can achive the same result as the field alias just by extracting the same value into two fields.
" ... (?<action1>(?<action_failed>....))..."
" ... (?<action1>(?<action_success>....))..."
Hope it helps.