Hello Team,
I need help in extracting the following date and time from the log,
sample log: -0900, 04.25.01 THU 22FEB24 nDD62320I
I need the 04.25.01 THU 22FEB24 part, could someone please help in extracting this using rex
Any help is much appreciated
Some like this:
,\s(\d\d\.\d\d\.\d\d\s\w+\s\d+\w+\d\d)\s
Or do you like to do it props.conf to set the _time field?
TIME_FORMAT = %z, %T %a %d%b%y
Try it out here: https://strftime.net/
Some like this:
,\s(\d\d\.\d\d\.\d\d\s\w+\s\d+\w+\d\d)\s
Or do you like to do it props.conf to set the _time field?
TIME_FORMAT = %z, %T %a %d%b%y
Try it out here: https://strftime.net/
hii,
it worked fine till February but for some reason the date is not getting extracted for March.
Could you please help here
want the date extracted for all the months..as the day goes by
I guess the first 9 days in every month has just one digit. This should do:
,\s(\d\d\.\d\d\.\d\d\s\w+\s+\d+\w+\d\d)\s
Added a + behind a space since it may be more than one space
TIME_FORMAT = %z, %T %a %e%b%y
Change a %d to %e
Hi
as @jotne has used %z as time zone information on props.conf you should add also this to your regex and then if/when needed use strptime and strftime functions to convert that field as needed. On ingestion time that happened automatically with correct TIME* definitions.
r. Ismo
Thank you so much for your great help 🙂
Hello @jotne ,
this is the regex: | rex field=_raw (?<date>\s(\d\d\.\d\d\.\d\d\s\w+\s\d+\w+\d\d)\s)