Hi,
Below is my sample payload. I want to convert/display it into a column value pair.
Eg, ESBTransactionID
75010569
Any help is appreciated.
75010569\n OCS\n \n Update\n TKT\n TKT\n \n OCS Driver\n \n OCS Driver\n \n 000141076513003\n false\n \n \n R_SUBBED\n TKT
| MAKERESULTS
| Eval s="75010569\n OCS\n \n Update\n TKT\n TKT\n \n OCS Driver\n \n OCS Driver\n \n 000141076513003\n false\n \n \n R_SUBBED\n TKT" |rex mode=sed field=s "s/\\n /=/g" | rex field=s max_match=0 "(?[^=]+)=(?[^=]+)" |fields transaction VALUE | fields - _time
See if this helps.
index=foo | rex "(?<ESBTransactionID>^\d{8})" | table ESBTransactionID
Like this?
Your search here
| rex "^(?<ESBTransactionID>\d+)"
| table ESBTransactionID