let's say we have events with _raw data like this:
The events can include a random amount of this pattern.
Is it possible to create an automatic field extraction to get:
priority = high
login = failed
user = johndoe
So position 3 of the pattern should set the fieldname while position 4 sets the value.
Thankd in advance
You can use props & transforms to do this:
FORMAT = $1::$2
REGEX = >\w+\,\w+\,(\w+)\,(\w+)
REPORT-fields-values = fields-values
Let me know how you get on.
View solution in original post
Awesome! Thanks works fine, thanks a lot
you are welcome! 🙂