I have the following
ACTION :[7] 'CONNECT'
DATABASE[1] 'SYSTEM'
That's in the _raw data.
How do I extract CONNECT and SYSTEM under headers ACTION and DATABASE?
Hi veera9,
Try this
ACTION\s:\[\d\]\s\'(?<ACTION>[^\']*)\'\s+DATABASE\[\d+\]\s\'(?<DATABASE>[^\']*)\'
You can test it at https://regex101.com/r/2BwU4O/1
Bye.
Giuseppe
That would be
| rex "ACTION\s:\[\d\]\s\'(?<ACTION>[^\']*)\'\s+DATABASE\[\d+\]\s\'(?<DATABASE>[^\']*)\'"
The above works fine. Based on your example breaking across lines, I might go with
| rex "ACTION\s:\[\d\]\s\'(?<ACTION>[^\']*)\'"
| rex "DATABASE\[\d+\]\s\'(?<DATABASE>[^\']*)\'"
...or...
| rex "ACTION\s:\[\d\]\s\'(?<ACTION>[^\']*)\'|DATABASE\[\d+\]\s\'(?<DATABASE>[^\']*)\'" max_match=0
Any of the above should work.
Thank you everyone.
If you're satisfied, please accept or upvote this answer.
Bye.
Giuseppe