Example:
My search is
index=* source=*xyz*
I am getting an event with plenty of lines in string format
I want to display 2 fields out of it as the example below:
[2021--2-12][info][xyz][empid=12345][cliner=123]....and so on... and empuniqid=123%abcd ..and so on...
From this I want display 2 fields empid and empuniqid
Any suggestions?
Thanks
If you only want these fields, just put them on a table command
| rex "empid=(?<empid>[^\]]+)"
| rex "empuniqid=(?<empuniqid>[^%]+)"
| table empid empuniqid
If you only want this to work if both these fields are in the _raw data, join the rex together
| rex "empid=(?<empid>[^\]]+).*empuniqid=(?<empuniqid>[^%]+)"
| table empid empuniqid
| rex "empid=(?<empid>[^\]]+)"
| rex "empuniqid=(?<empuniqid>[^%]+)"
Not working with this solution
In what way does it not work?
This solution assumes the data is in the _raw field and that empid is terminated by ] and empuniqid is terminated by %. If these are not the terminators, you can adjust the rex appropriately. If this still doesn't work, please be more specific about what exactly you are trying to extract from the data.
index=* source=*xyz*
I am getting an event with plenty of lines in one event string format
I want to display 2 fields out of it as the example below:
[2021--2-12][info][xyz][empid=12345][cliner=123]....and so on... and empuniqid=123%abcd ..and so on..
If it is empleid and empuniqid are in single string and I want to delete all the data except 12345 and 123.
The expected output should be:
empleid. empuniqid
12345 123
If you only want these fields, just put them on a table command
| rex "empid=(?<empid>[^\]]+)"
| rex "empuniqid=(?<empuniqid>[^%]+)"
| table empid empuniqid
If you only want this to work if both these fields are in the _raw data, join the rex together
| rex "empid=(?<empid>[^\]]+).*empuniqid=(?<empuniqid>[^%]+)"
| table empid empuniqid
@ITWhisperer the first part from
| rex "empid=(?<empid>[^\]]+).*empuniqid=(?<empuniqid>[^%]+)" | table empid empuniqid
I mean the empid is able to fetch but the empuniqid is not actually for some fields there is no %, I want the data from the raw data from the middle and there is no delimiter ;
Please refer the below example for more understanding :
[2021--2-12][info][xyz][empid=12345][cliner=123]....and so on... and empuniqid=123%abcd ..and so on.
and some times my data varies to
[2021--2-12][info][xyz][empid=12345][cliner=123]....and so on... and empuniqid=12345678 ..and so on.
I want 1234 from second line and 123 from first line,
Thank you so much for you help
How do you know how much of the empuniqid you want? If there is no delimiter, is it up to four numbers from the beginning of the id? Or something else?
| rex "empid=(?<empid>[^\]]+).*empuniqid=(?<empuniqid>\d{1,4})"
| table empid empuniqid