Scenario, I have a field (msg) below and I need to extract the user id which is user = [abcdefg]
field msg = AAA user accounting Successful : server = 192.168.0.1 : user = abcdefg
index = main | rex field=msg [?] ....
I need the abcdefg portion.
Thank you!
Assuming the value is terminated by a space, this should do the job.
... | rex field=msg "user = (?<user>[^ ]*)" | ...
Assuming the value is terminated by a space, this should do the job.
... | rex field=msg "user = (?<user>[^ ]*)" | ...
only getting a single character under stats list(user)
I forgot the quantifier (*). Try the updated answer.
Thank you, will have to test later, someone just restarted my indexer....
Sweet!!!! it works great! Thank you