I need to fetch the 'InterfaceName' from the below payload. I built a regular expression but it is not working as expression. Can someone please verify this and correct me where I am wrong.
I created one regex expression like - | rex field=_raw "ns:InterfaceName\W+(?<AppId>\w+)" |stats count by AppId.
From the above expression I am getting only double quotes ("), but unable to fetch data.
Thanks in advance.
Here's an alternative regex to try.
View solution in original post