My Raw log says "message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc)"
I wanted to extract everything inside the Parentheses ( )
Thanks in advance.
Like this?
| rex "message: \((?<in_parentheseses>[^\)]+)"
You can test with
| makeresults format=csv data="_raw
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc)"
``` data emulation above ```
| rex "message: \((?<in_parentheses>[^\)]+)"
_raw | in_parentheses |
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc) | c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc |
Thank you for the help @yuanliu
Like this?
| rex "message: \((?<in_parentheseses>[^\)]+)"
You can test with
| makeresults format=csv data="_raw
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc)"
``` data emulation above ```
| rex "message: \((?<in_parentheses>[^\)]+)"
_raw | in_parentheses |
message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc) | c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc |