could you please anyone help me to write the regex for below statement and need extract the external value from below logs.
Give this a try:
|rex field=_raw "EXTERNAL\:(?P<EXTERNAL>.[^\s]*)"
View solution in original post
... my search here | rex field=_raw "EXTERNAL:(?<EXTERNAL>\d+\.\d+\.\d+\.\d+\/\d+)"
You can see it works in this example at regex101.com.
thank for the information adayton and i tried with above search and not receiving any value under the External.
AFAIK shouldn't have to use a backward slash on colons.
adayton and zanb , the below command is working fine.
rex field=_raw "EXTERNAL:(?P.[^\s]*)"
Can you provide a sample of the raw log, please?