Hi,
I am having the following query:
index=* sourcetype=CustomAccessLog | table "host", "source"
The output is:
| host | source |
| server32.de.db.com | /path/to/server/instances/IFM_RT_1/logs/subdir_logs/log.file |
| server31.de.db.com | /path/to/server/instances/IFM_RT_2/logs/subdir_logs/log.file |
I would need to alter the search query so that the output is becoming:
| host | source |
| 32 | IFM_RT_1 |
| 31 | IFM_RT_2 |
Tried using the following for the IFM_RT_
index=* sourcetype=CustomAccessLog | rex field=_raw "(?<IFM_RT_>.*)", but I couldn't get the needed data.
Can I have your help here?
Thanks!
Hi @jugarugabi,
you could try to use the following regexes:
index=* sourcetype=CustomAccessLog
| rex field=source "(?<source>IFM_RT_\d*)"
| rex field=host "^server(?<host>\d+)"
| table host sourceCiao.
Giuseppe
Hi @jugarugabi,
you could try to use the following regexes:
index=* sourcetype=CustomAccessLog
| rex field=source "(?<source>IFM_RT_\d*)"
| rex field=host "^server(?<host>\d+)"
| table host sourceCiao.
Giuseppe
Hi @jugarugabi,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉