I have the following string pattern (source):
Now I need to create at search following fields:
- DBSID, being "BWP" in this case
- servis, being the "xsengine"
- filename, being "xsengine_ls5925.30246.crashdump.20190312-213001.009072.trc"
For the filename I managed to find the following:
| rex field=source "(?<filename>[\w\d\.-]+$)"
But somehow I struggle with the first two ...
| eval log="/trace/DB_BWP/xsengine_ls5925.30246.crashdump.20190312-213001.009072.trc"
| rex field=log "\/.+_(?P<DBSID>.+)\/(?P<servis>.+)\_(?<filename>.+)$"
| eval filename = servis."_".filename
View solution in original post
Thank you, it work fine.