Hi, I am trying to setup a dropdown bar for a dashboard and would like to setup dynamic inputs based on the source log file, as there are many different sites being built and torn down.
example source log name:
I would like to extract "example.com.au" from the above source log file and drop everything else. Then make it a distinct value. This value would then be selectable in the dropdown bar to filter on that site.
This is what I've attempted but is not returning what I need.
index=example sourcetype=test:access | eval baseurl = mvindex(split(source,"/", -1) | top baseurl
Thanks in advance.
The following should work for you to extract the part you want from the
index=example sourcetype=test:access | rex field=source "\\(?P<file>[^_\\]+)_[^\\]$"
Thank you for answering. I ran the search with the rex you provided and got the following error:
Error in 'rex' command: Encountered the following error while compiling the regex '(?P[^]+)[^]$': Regex: missing terminating ] for character class
Hi thanks for you help, but I'm also getting an error when I run your rex:
Error in 'rex' command: Encountered the following error while compiling the regex 'logs(
I've managed to get it working using
rex field=source "\w+\(?P[\w+]+)_accessLog\S+$"| top 20 site