Hi everyone,
I'm struggling with this rex expression:
query | rex field=source "/var/syslog*(?<remote_source>\w+)/*.log"
/var/syslog/name_folder/2015-08-11.log
I need to get the folder name. Could someone please help me to correct this regex?
Thank you a lot! : )
Like this:
query | rex field=source "^\/(?:[^\/]+\/){2}(?<remote_source>[^\/]+)\/"
Like this:
query | rex field=source "^\/(?:[^\/]+\/){2}(?<remote_source>[^\/]+)\/"
Don't forget the escape characters.
^\/(?:[^\/]+\/){2}([^\/]+)\/
quite correct; Fixed another markdown mistake, too (answer updated and tested).
Thank you : )