I got a variable called _host_name which = usscic-secfio102.na.xxx.com. I need to derive a variable called host_short which will have the value of usscic-secfio102 -- I use Ruby Regular expression editor to figure out expression to get string i need -- it's ^\w+.\w+ How do I integrate in querty using rex?
index=cisco sourcetype=cisco_asa AND vendor_action=permitted AND host=158.11.333.444 | eval service=transport."/".dest_port| lookup dnslookup ip as host output host as host_name| rex????? | table host_short
thanks ... that was easy
rex field=called _host_name "(?<short_host>[^\.]+)"
how about this?