Hi,
I have this sample log and I want to extract the request ID value after the period. Each of those numbers are unique in my log file.
Timeout sending message for request ID.140445678
I've tried various ways but cannot come up with working rex command that would extract those values as a field.
... | rex field=_raw "request <(?w+)>"
Any assistance would be awesome, thanks so much.
Try this:
... | rex "(?<request>\d+)[\r\n\s]*$"
You can try this,
| makeresults
| eval data="Timeout sending message for request ID.140445678"
| rename data as _raw
| rex "request\sID\.(?P<request_id>.*)"
@philgopaul ,
Try
|rex field=_raw "request ID\.(?<request_id>\d+)"