I have a log which contain multiple countries in same format so it grabbing all other countries from same individual log . for example: Student:{"country":"IND","firstName":"XYZ","state":"MH",...
See more...
I have a log which contain multiple countries in same format so it grabbing all other countries from same individual log . for example: Student:{"country":"IND","firstName":"XYZ","state":"MH","rollNum":147,"phoneNum":1478,"lastName":"qwe","phoneNu} teacher:{"country":"USA","firstName":"XYZ","state":"MH","rollNum":147,"phoneNum":1478,"lastName":"qwe","phoneNu} So if i use | rex field=_raw "\"country\":\"(?<country>[^\"]+)\"" it showing me IND and USA. but i only want country related to student. Also as i stated earlier position of "country":"*" is not same for all logs. its coming between anywhere Student:{*}