index=whatever* sourcetype=server earliest=-3d | table USERNAME CLIENT_VERSION_IN |where NOT isnull(SU_USERNAME_IN)|where CLIENT_VERSION_IN=*07_2*
CLIENT_VERSION_IN=*07_2*
doesnot seem to work as the value here 'XF_07_2_5474'. Can some one help build a rex or regex so that i could get the data.
Thanks
Hi alladin101,
if you want to get something between two '
single quotes, try something like this:
... | head 1 | eval foo="'XF_07_2_5474'" | rex field=foo "\'(?P<myfoo>.+)\'" | table foo myfo
and the result will be like this:
hope this helps ...
cheers, MuS
this works but i want to use a wild card here in this part :eval foo="'XF_07_2_5474'"
as 5474 may vary. Is that possible?
can you mark this as answered as well - thx
In terms more close to your question, with MuS's reply, use:
index=whatever* sourcetype=server earliest=-3d | table USERNAME CLIENT_VERSION_IN | rex field=CLIENT_VERSION_IN "\'(?P<fixedfield>.+)\'" | table CLIENT_VERSION_IN fixedfield
Completely generic for your case as provided.
I must admit, I don't fully understand your intensions but sure this will work:
| eval foo="'XF_07_2_*'" | rex field=foo "\'(?P<myfoo>.+)\'" | table foo myfoo
will result in a table looking like this:
foo myfoo
'XF_07_2_*' XF_07_2_*