Hi, I need help to extract a value from field named "message".
Field "message" value is as below:
The process C:\Windows\system32\winlogon.exe (PRD01) has initiated the power off of computer PC01 on behalf of user ADMIN JABATAN for the following reason: No title for this reason could be found
The process C:\Windows\system32\shutdown.exe (PRD01) has initiated the restart of computer PC01 on behalf of user ADMIN\SUPPORT for the following reason: No title for this reason could be found
The process C:\Windows\system32\shutdown.exe (PRD01) has initiated the restart of computer PC01 on behalf of user admin for the following reason: No title for this reason could be found
The value i want to extract is:
newField |
ADMIN JABATAN |
ADMIN\SUPPORT |
admin |
Please assist. Thanks.
Hi,
your search
| rex field=message "of\suser\s(?<new_user>.+?)\sfor\sthe"
this command extract new_user field.
Hi @batabay, thank you for the response. It works!
Hi,
your search
| rex field=message "of\suser\s(?<new_user>.+?)\sfor\sthe"
this command extract new_user field.