I have a field which has a random value in between (value can be anything. representing it by * here).
Field= test_field
value: test/documents/*/check
How do I group by this field since the value is always different and gives me different rows when I try to group by field test_field
?
Like this:
... | rex field=test_field "^(?<firstHalf>(?:[^/]+/){2})[^/]+/(?<secondHalf>.*)$" | eval Normalized_test_field = firstHalf . "*/" . secondHalf | stats <somestuff> BY Normalized_test_field
If this worked, please do click "Accept".