Hello
I want to extract the field below from my event
ABDM-TOUPDATE.$w$
could you help me please?
Pls check this run-anywhere example -
(please provide some logs and more details, so that exact rex query can be written -)
| makeresults
| eval _raw = "something something ABDM-TOUPDATE.5w2 something something"
| rex field=_raw "(?P<rexHELP>ABDM-TOUPDATE\.\d\w\d)"
| table _raw rexHELP
Pls check this run-anywhere example -
(please provide some logs and more details, so that exact rex query can be written -)
| makeresults
| eval _raw = "something something ABDM-TOUPDATE.5w2 something something"
| rex field=_raw "(?P<rexHELP>ABDM-TOUPDATE\.\d\w\d)"
| table _raw rexHELP
could you please share what needs to be extracted and whats your raw event?
I cant sent the raw event because confidentiality
in my event, i just want to extract this: ABDM-TOUPDATE.$w$
Just that literal string? Or are those $
signs placeholders of something?
And what do you want to extract it from and where do you want to extract it into?
Simple example extracting from _raw
into field1
: | rex field=_raw "(?<field1>ABDM-TOUPDATE\.\$w\$)"