How to extract fields from below source.
/audit/logs/QTEST/qtestw-core_server4-core_server4.log
I need extract QTEST as environment qtestw as hostname core_server4 as component core_server4.log as filename
Hi @karthi2809 ,
you can use this regex:
| rex field=source "^\/\w+\/\w+\/(?<environment>\w+)\/\w+-(?<component>[^-]+)-(?<filename>.*)"
you can test this regex at https://regex101.com/r/0VJvAw/1
Ciao.
Giuseppe
Try this :
<your_search>|rex field=source "\/audit\/logs\/(?<environment>[^\/]*)\/(?<hostname>[^-]*)\-(?<component>[^-]*)\-(?<filename>.*$)"
------
Hi @karthi2809 ,
you can use this regex:
| rex field=source "^\/\w+\/\w+\/(?<environment>\w+)\/\w+-(?<component>[^-]+)-(?<filename>.*)"
you can test this regex at https://regex101.com/r/0VJvAw/1
Ciao.
Giuseppe