I have a question for you, and I need your help please 🙂
I have some logs, but the parsing isn't done.
In a same log, I have a lot of indicators and I need to extract the fields :
- mac_addresses: [
- name: PCW-TOU-76566
- number_of_monitors: 3
- os_version_and_architecture: Windows 10 Pro 21H2 (64 bits)
- platform: windows
- score:Device performance/Boot speed: null
- system_drive_usage: 0.19
- total_nonsystem_drive_capacity: 0
The log is like this :
What can I do to have the fields extracted to develop my indicators ?
The regex method is not possible in this case, can I use rex command ? and how I can do for this example ?
I need your help, thank you so much
This looks like JSON. Use the spath command