Hello All, I am just learning Splunk and using rex but could you guys help me with my syntax to assist me in extract specific information from the Message table? Here is my sample syntax: host="*<hostname>" EventCode=4624 OR EventCode=4724 | table _time host user Message | dedup user Results in Message: "An account was successfully logged on. Subject: Security ID: Account Name: Account Domain: LogonID: ETC" I really just want to pull the first part where it says "An account was successfully logged on." Or the first part of any message that does not need include the rest of the Message after. I know the syntax of the search could most definitely be better but I am just learning how to do these searches so if anyone has a better recommendation on how to do these searches please let me know. Otherwise if you could recommend how to filter the rest out through rex, that would be awesome as well! Thank you all in advance!
... View more