Hi,
I have diff log formats in a single sourcetype. Thus can't define field extraction - is there way to use REX in the search string itself which creates fields.?
My log looks like this -
Aug 21 20:44:38, ip-10-237-103-12.ec2.internal, vehicle-master-stg, LOG_MESSAGE:
Fix your sourcetypes before doing anything else. This will get much worse down the road