I want to extract exception, key and message from a raw event in our logs. The event looks like:
EXCEPTION - : TypeOfException : keyprefix.keyName : Message from web service
From the event I use REX to get the following:
exception=TypeOfException
key=keyprefix.keyName
message=Message from web service
I am using the following rex for it:
rex field=_raw "EXCEPTION - : (?
But this isn't working. Can you guys point me in the right direction?
I have tried various combinations of these inserting spaces (\s) where we see spaces in the event.
Ok. Found the answer:
rex field=_raw "EXCEPTION\s-\s\s:(?
Ok. Found the answer:
rex field=_raw "EXCEPTION\s-\s\s:(?