Hi,
I am struggeling with field extractions. I have two fields that I want to extract. But the problem is sometimes te value is in 'Documentid : 123456789' and sometimes in 'DocumentId 123456789' so without the :
Is it possible to make an extraction that extracts only the numbers after 'DocumentId' ?
So, is your actual example with either a space or a colon but not both?
| rex "DocumentId(:| )(?<documentid>\d+)"
It might help if you paste your examples in a code block </> so it doesn't get auto-formatted
@ITWhisperer Thank you. I made a mistake with he examples
DocumentId 47335252
DocumentId:47337177
I changed your regex to : | rex DocumentId:?(?<documentid>\d+) but then it does not recognize the first example (DocumentId:47337177 ) I wish I could understand regex more to fix it myself
So, is your actual example with either a space or a colon but not both?
| rex "DocumentId(:| )(?<documentid>\d+)"
It might help if you paste your examples in a code block </> so it doesn't get auto-formatted
Yes, its either colon or a space. Your last reply worked. Thank you
Assuming it is just the colon that is missing and the two spaces are there:
| rex "Documentid :? (?<documentid>\d+)"