I am trying to do a field extraction for a log ...the issue I am facing is the field lay out remains constant works fine for 90 % time but for remaining 10 % the log format changes
when I have a message line with "Authenticated" In there the userID is 9 th field
BUT when I have "LOGOFF" in the line the UserID is coming in as 7 th field .
How do I define my props/transforms so I am capturing ALL User_IDs irrespective If it comes in 7 th field or 9 th field ?
Thanks for the help !
And a few lines from a log file, showing the alternate formats, would be helpful, too. You should anonymize any identifying data. Thanks!
if for example you have:
First Kind of event,Some More field,Authentication,7,More,More
Second Kind of event,Data,Data,Data,Data,Data,Data,LogOFF,7,More,More
if you want to get the 7