I am looking through our current alerts and we have a few evaluations that occur like below.
Total_Trade: 129
Total_Value: 300
Total_Amount: 1000
I have a rex like below:
| rex max_match=0 Total_(?<Type>\w+):(?<amount>\w+)
Doing this though I get two fields with multiple events like below.
Type | amount |
Trade Value Amount |
129 300 1000 |
What I wanted was each of these to be separate though/
Type | amount |
Trade |
129 |
Value | 300 |
Amount | 1000 |
| rex max_match=0 "Total_(?<Typeamount>\w+:\s*\w+)"
| mvexpand Typeamount
| rex field=Typeamount "(?<Type>\w+):\s*(?<amount>\w+)"