Hi, I have the below output : 1/16/2023 7:51:43 AM 1EE8 PACKET 000001D9C25E6180 UDP Rcv 10.8.64.132 646b Q [0001 D NOERROR] A (6)framer(3)com(0) UDP question info at 000001D9C25E6180 Socket = 940 Remote addr 10.8.64.132, port 55646 Time Query=9030678, Queued=0, Expire=0 Buf length = 0x0fa0 (4000) Msg length = 0x001c (28) Message: XID 0x646b Flags 0x0100 The desired output name=framer.com IP=10.8.64.132 I using regex: sourcetype=DNSlog |rex field=_raw "NOERROR]\W+(?P<name>.*)\sUDP \S.*\s Socket.*\s Remote addr\W+(?P<IP>.*)," | rex mode=sed field=name "s/[\d;()]+//g" |stats count by name IP My below code isn't working, can you please help me?
... View more