When i search for the string "ERROR" in a log i get the below
<
DEBUG : blah blah
INFO : blah blah blah
ERROR : <some error string>
More blah blah
>
I want to only show the whole line that starts with ERROR. The length of the error line is variable.
How can i do this?
I do understand that fixing the line breaks formatting in prop.conf might be a quicker way but i dont have access to that file so would like to do it in the result head. thanks in advance.
Hi @HelloItsMe76,
You can use regex to extract the error string using below command after your search This will create a new field error_string that contains ERROR line info.
| rex field=_raw "ERROR\s+:\s+(?<error_string>.+)"
Hi @HelloItsMe76,
You can use regex to extract the error string using below command after your search This will create a new field error_string that contains ERROR line info.
| rex field=_raw "ERROR\s+:\s+(?<error_string>.+)"
thanks, that worked.