Hi Team,
Can someone Kindly help with a rex pattern for the below splunk log.
Attached a sample splunk log and rx pattern for reference.
Sample splunk log:
TransferStatus.Id: "63636_#^#^#_#737373646_÷",
user=FileactiveHeartBeat,
Sample Rex command:
| rex "TransferStatus.Id: \\\\\"(?<transfer_id>.+?)\\\\\""
| rex "user=(?<customer>.+?),"
Need a similar rex pattern for the below splunk log
"transferId":"37373773-yeye-eueueh-9172",
"userName":"dudhkd",
The second log looks like JSON - why not process it as such?
Assuming you still want to use rex (not necessarily the best way to do this), you could try this
| makeresults
| fields - _time
| eval _raw="TransferStatus.Id: \"63636_#^#^#_#737373646_÷\",
user=FileactiveHeartBeat,
\"transferId\":\"37373773-yeye-eueueh-9172\",
\"userName\":\"dudhkd\","
| rex "TransferStatus.Id: \\\"(?<transfer_id>.+?)\\\""
| rex "user=(?<customer>.+?),"
| rex "\"transferId\":\"(?<transfer_id_2>.+?)\""
| rex "\"userName\":\"(?<customer_2>.*?)\""