Hi Guys,
I have to extract one field from the below log and i tried this regex in https://rubular.com/ "(?<=^4Nett\s\W\W)(\W.*)$" This regex exactly working what i am looking for.
Status report: "<App name> :: <Status>"
ABC_Service :: Started in 2 sec
but when i try this in splunk it is not giving me the extracted field.
<base query>|rex (?<Application_status><=^4Nett\s\W\W)(\W.*)$
My expected result
Started in 2 sec
Please give me a hint what i am missing here
@dineshCool,
If you have the :: delimiter always in the events try
rex "::\s+(?<Application_Status>.*)"
@dineshCool,
If you have the :: delimiter always in the events try
rex "::\s+(?<Application_Status>.*)"