example
[dto=forename: "abcforename"
surname: "abcsurname" ..................]
I want to extract the forename and surname ,
and let them combine as a field USER
how?
MANY THX.
You would have to tune the regex to match your requirement but the query would be somewhat like below
.. | rex field=fieldnamehere "dto\=forename\:\s\"(?<fname>\w+)\"\ssurname\:\s\"(?<sname>\w+)\"" | eval merged=fname." ".sname
You would have to tune the regex to match your requirement but the query would be somewhat like below
.. | rex field=fieldnamehere "dto\=forename\:\s\"(?<fname>\w+)\"\ssurname\:\s\"(?<sname>\w+)\"" | eval merged=fname." ".sname
Use a multiline rex.. This will capture everything in the "..".
search.... | rex field=_raw "^\[dto=forename\:\s\"(?<fname>.*)\"\nsurname\:\s\"(?<lastname>.*)\"" | table forename lastname
Another option would be to use props, set your sourcetype with linemerge=false, and define your event boundaries.