Hi,
I have a logfile containing data that looks like the below:
Nov 21 13:59:41
hostname1
data1
data2
data3
Nov 21 13:59:42
hostname1
data1
data2
data3
Nov 21 13:59:43
hostname1
data1
data2
data3
I would like to extract hostname, and each data in a separate line.
How can I configure the regex to get such fields?
Thanks in advance,
Splunk should already parse out each section, splitting on the timestamp, to a separate "record". This regex will work for the sample you've provided:
rex "(?m)(?
Splunk should already parse out each section, splitting on the timestamp, to a separate "record". This regex will work for the sample you've provided:
rex "(?m)(?
That's great, thanks!