I have a search that gives me a bunch of fields that look like:
REBOOT=4/5/2016 9:17:19 AM
REBOOT=4/5/2016 9:12:02 AM
REBOOT=4/5/2016 8:58:28 AM
How can I remove the REBOOT= and keep the date/time with my search
If the "REBOOT=4/5/2016 9:17:19 AM
" appear as a value for a field, you can do like htis
your base search | replace "REBOOT=*" with * in yourfieldname(s)
If this appears in the raw data, try like this
your base search | rex mode=sed "s/REBOOT=//g"
If the "REBOOT=4/5/2016 9:17:19 AM
" appear as a value for a field, you can do like htis
your base search | replace "REBOOT=*" with * in yourfieldname(s)
If this appears in the raw data, try like this
your base search | rex mode=sed "s/REBOOT=//g"
Thanks, that's what I was looking for.
Chad