Hello - I need help extracting the "hostname" value into a separate field in the following string:
ABC1234: VPN Tunneling: Session started for user with IPv4 address 10.10.10.10, hostname jsmith-1234s
| rex "hostname (?<hostname>[^\s]*)"
View solution in original post
Ah, this DID work! There was a temporary problem with our data that caused an issue. Thank you!
That didn't seem to work - no results were produced. The hostname string is within a field called "msg" if that matters (though I tried plugging that in and still can't get results).