I have events that look like this and I am using the field extractor "timestamp": "2020-12-09T18:05:03.6664112Z", "scopeType": "organization", "scopeDisplayName": "1D (Organization)", "scope...
See more...
I have events that look like this and I am using the field extractor "timestamp": "2020-12-09T18:05:03.6664112Z", "scopeType": "organization", "scopeDisplayName": "1D (Organization)", "scopeId": "920941ec-025f-4d4c-9944-e7d357de7d94", "actionId": "Deleted", "data": { "ProjectName": "ATI Libs", "RepoId": "eb1e2a37-0833-462a-b3e6-031aa1d1f006", "RepoName": "libs-01" }, I tried to extract fields using both delimited option ":" as well as using regex. When I use delimiter of "," it creates the first field 'timestamp' correctly but then lumps everything after that into a single field. When I try to use regex to extract a field, for example I highlight the value "ATI Libs", I get this error: "The extraction failed. If you are extracting multiple fields, try removing one or more fields. Start with extractions that are embedded within longer text strings." Please advise, thanks.