Given my apache access_log URI is /Foobar/FoobarServices, I want to extract Foobar only for my timechart. makemv delim="/" allowempty=t uri returns Foobar and FoobarServices. All I want is the Foobar. How do I do that?
makemv delim="/" allowempty=t uri | timechart count by uri
Thanks!
Got it
sourcetype="access_combined" | rex field=uri "^/(?
Thanks!
Cool, please accept the answer and select the up arrow then.
Got it
sourcetype="access_combined" | rex field=uri "^/(?
Thanks!
Did you get a new field on the left called newfield with this information?
Yes. I tried your recommendation and I still get /Foobar/FoobarServices. I just want to capture Foobar.
Are you just trying to extract information between the / and create a new field?
sourcetype="access_combined" | rex field=uri "^/(?
Something like this?