My current search is:
index=rtm* source=/prod/msp/logs/private-auto-loan-credit* | regex "The rule (?<field1>[a-zA-Z0-9]+_[a-zA-Z0-9]+)_(?<field2>[a-zA-Z0-9]+) with" | table field1, field2
In verbose mode, it finds the correct entries, but my table is full of nulls. What am I doing wrong?
Hi
can you share example events so the community could help you.
You should change regex to rex and try again.
r. Ismo