Hello everyone,
I've been banging my head on this one. I'm sure it involves 'rex' which I'm not so familiar with.
I have the following search
search | regex _raw="|MAX TCP Connections||MAX UDP Connections|" | table _raw
Of course this spits out the entire _raw event. I'd like search for all events that match event with either MAX TCP Connection or MAX UDP Connection and send those to a field and when I use table, I see either MAX TCP Connections or MAX UDP Connections in the field. No event will have both. I really hope that makes sense. Any help would be great.
... View more