"sessionID":"123456567"
"sessionID":"ABCnsh8ah"
Please help me with Rex to pick
123456567
ABCnsh8ah
from above _raw event
Please try
<raw_search> | rex "sessionID\":\"(?<mysessionID>[\d\w]+)\""| table mysessionID
Full example with sample data
|makeresults | eval _raw="\"sessionID\":\"123456567\""| rex "sessionID\":\"(?<mysessionID>[\d\w]+)\""| table mysessionID
Hi,
Give this a shot:
rex field=_raw> "\"sessionID\":\"(?<field>\S+)\""
Try this:
| rex field=_raw "sessionID\"\:\"(<sessionID>.[^\"]*)"
Please try
<raw_search> | rex "sessionID\":\"(?<mysessionID>[\d\w]+)\""| table mysessionID
Full example with sample data
|makeresults | eval _raw="\"sessionID\":\"123456567\""| rex "sessionID\":\"(?<mysessionID>[\d\w]+)\""| table mysessionID