2018-07-28 12:55:48 ET GOT /itune/odb/1234567/sms/unread/count?_=123456 200 A1D2F3G45H6HY6@AK C1FV2G32G3HH34H+mP4yT+12gc= 10.131.42.16 0.013
Hi This is my sample dynamic data , we have to create raw fields and create a table with the following fields...URI,STATUS CODE, REQID, SESSIONID
Can anyone help me the query with the following fields
| rex field=_raw "(?P<date>\d+-\d+-\d+\s\d+:\d+:\d+)\s\S+\s\S+\s(?P<URI>\S+)\s(?P<status>\d+)\s(?P<code>\S+.*)\s(?P<REQID>\d+.\d+.\d+.\d+)\s(?P<SESSIONID>\d+.\d+)"
Thank you for your reply. Its not working for me, looks like i am not explain teh question to you properly. I will share more details.
sure. In between i had a typo in the query. Please check again