When i try to extract BiosMake fields in my log file with field extraction (Mode regex).I have this:Error in 'rex' command: regex="^\w+="\d+\.\d+\.\d+\.\d+"\s+\w+=\w+\d+\s+\w+=\d+\s+\w+=\w+\-\w+\s+\d+\-\w+\s+\w+=\d+\.\d+\s+\w+=\w+\d+\s+\w+\.\s+\d+\.\d+\.\d+\s+\w+=\d+\s+\w+=\d+\w+\d+\s+\d+:\d+:\d+\.\d+\s+\w+=\w+\.\w+\.\w+\\\w+\-\w+\-\w+\d+\w+\s+\w+=\w+\d+\s+\w+\s+\d+\s+\w+\s+\w+=\w+\s+\w+\s+\w+=\w+\d+\s+\w+=(?P<volumeEncryptionState>\w+)" has exceeded configured match_limit, consider raising the value in limits.conf
this is my log:
Hi @christian75,
if your volumeEncryptionState field hasn't any space in the value, please try this regex
| rex "volumeEncryptionState\=(?<volumeEncryptionState>[^ ]+)"
that you can test at https://regex101.com/r/nejG4v/1
otherwise, please test this:
| rex "volumeEncryptionState\=(?<volumeEncryptionState>.+)\s+TpmMake"
that you can test at https://regex101.com/r/nejG4v/2
Ciao.
Giuseppe
Do you not need to escape the embedded double quotes?
regex="^\w+=\"\d+\.\d+\.\d+\.\d+\"\s+\w+=\w+\d+\s+\w+=\d+\s+\w+=\w+\-\w+\s+\d+\-\w+\s+\w+=\d+\.\d+\s+\w+=\w+\d+\s+\w+\.\s+\d+\.\d+\.\d+\s+\w+=\d+\s+\w+=\d+\w+\d+\s+\d+:\d+:\d+\.\d+\s+\w+=\w+\.\w+\.\w+\\\w+\-\w+\-\w+\d+\w+\s+\w+=\w+\d+\s+\w+\s+\d+\s+\w+\s+\w+=\w+\s+\w+\s+\w+=\w+\d+\s+\w+=(?P<volumeEncryptionState>\w+)"
Hi @christian75
I suppose your regex is to heavy and generate and error anyway I suggest to use automatic key value extraction
however if you need a new light regex you can use this:
BiosMake=(?<biosmake>[^ ].+)
hope can help
Ale