Splunk Search
Highlighted

How can I exract these error messages into one field?

Communicator

|| vasb05 | PROD | Availit | | 2017-08-11 08:54:01,420 | ERROR | http--10.100.108.48-8080-13 | com.amerigroup.utilities.FileTransferManager.saveFile(FileTransferManager.java:120) | Unable to write file data to \agpcorp\apps\Local\BatchJava\Prod\attachments\ClaimAppeals\14460311450020170811T0854011CLAIM.pdf: java.io.FileNotFoundException: \agpcorp\apps\Local\BatchJava\Prod\attachments\ClaimAppeals\14460311450020170811T0854011CLAIM.pdf (There is not enough space on the disk)

italic field to extract

0 Karma
Highlighted

Re: How can I exract these error messages into one field?

SplunkTrust
SplunkTrust

Do you want to extract the fields at index time or search time?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How can I exract these error messages into one field?

SplunkTrust
SplunkTrust

At search time, do this...

| rex "(|[^|]*){6}| ERROR\s+(|[^|]*){2}|(?<errormessage>.*)"
0 Karma