I am looking through our current alerts and we have a few evaluations that occur like below.
Total_Trade: 129
Total_Value: 300
Total_Amount: 1000
I have a rex like below:
| rex max_match=0 Total_(?<Type>\w+):(?<amount>\w+)
Doing this though I get two fields with multiple events like below.
| Type | amount |
| Trade Value Amount |
129 300 1000 |
What I wanted was each of these to be separate though/
| Type | amount |
|
Trade |
129 |
| Value | 300 |
| Amount | 1000 |
| rex max_match=0 "Total_(?<Typeamount>\w+:\s*\w+)"
| mvexpand Typeamount
| rex field=Typeamount "(?<Type>\w+):\s*(?<amount>\w+)"