How do i take out the port number (portnr) from the args field and make it to a field called "port" by a search? Can the answer here be to use eval
and rex
?
Yes , you can use this rex command to get port- rex field=Args "_(?<port>\d{4})_"
Yes , you can use this rex command to get port- rex field=Args "_(?<port>\d{4})_"
Thanks :). Do you think i will need to use eval here? or will it just be fine to use rex ?
rex will be fine, no need for eval if you just want to get port number in port field.
My logline her is:
_time command Args
24.05.1998 17:54 splunkA A_4040_restart
4040 is the portnr. I just want to take out portnr and put it a new field called port
try this
YOUR_SEARCH | rex field=args "_(?<port>.*)_"
Sample:
| makeresults | eval args="A_4040_restart" | rex field=args "_(?<port>.*)_"
Thank you very much!
try
YOUR_SEARCH | rename portnr as port
Thanks for your reply! But my full question was:
My logline her is:
_time command Args // fields
24.05.1998 17:54 splunkA A_4040_restart //Values
4040 is the portnr. I just want to take out portnr and put it a new field called port