Below is the sample field value from the event,
sourceServiceName=Endpoint Web analyzedBy=Policy Engine Status=New Success=True
By default, the field value detects only Endpoint and not the full text Endpoint Web
Som I used the below rex command but it didn't work,
rex "sourceServiceName=(?<sourceServiceName>[^\"]+)" - This one fetches all the text starting from "Endpoint to end of that event"
Also the value of the field sourceServiceName can be anything, i.e -Endpoint Web or Endpoint Printing Endpoint USB etc. First word -Endpoint Second word -any can any word
I want to fetch only the value of field serviceSourceName
Can you please help?
Hi
you could try this
index=_internal
| head 1
| eval _raw = "sourceServiceName=Endpoint Web analyzedBy=Policy Engine Status=New Success=True Some=Other fields"
```Previous was set up the data, next one is the logic```
| rex "sourceServiceName=(?<sourceServiceName>[\w\s]+)\s+\w+="
r. Ismo
Thanks a lot. It worked
Hi
you could try this
index=_internal
| head 1
| eval _raw = "sourceServiceName=Endpoint Web analyzedBy=Policy Engine Status=New Success=True Some=Other fields"
```Previous was set up the data, next one is the logic```
| rex "sourceServiceName=(?<sourceServiceName>[\w\s]+)\s+\w+="
r. Ismo