I need to perform a search that extracts user ids from unformatted log lines where the user id would be extracted by one of the following rex commands.
Conceptually it would be something like:
| rex field=_raw "Users\\\(?<xxx>\w*)"
OR rex field=_raw ": FEDERATED\\\(?<xxx>\w*)"
OR rex field=_raw "user FEDERATED\\\(?<xxx>\w*)"
| eval xxx=upper(xxx) | stats values(xxx)
So, it is essentially three searches with the results to be combined. Does this make any sense?
The best thing to do would probably be to use props and transforms. If you define each of these rex commands as a REPORT transform you can then specify multiple in your props.conf and the first successful extraction will be used. See that here: