Can't seem to make this work.. using a " " delimter in my transforms didn't do the trick..
www-ber 10/18/2013-02:59 85 up OK
www-pcr 10/18/2013-01:44 64 down HTTP Error 503
Any suggestions?
Did you use DELIMS=" "
? And it didn't work because you have some strings with spaces that you wanted to extract as one field? Then perhaps you should try a different approach;
props.conf
[your sourcetype]
EXTRACT-blah = ^(?<field1>\S+)\s+(?<field2>\S+)\s+(?<field3>\d+\s\w+)\s(?<field4>.*)
/K
Did you use DELIMS=" "
? And it didn't work because you have some strings with spaces that you wanted to extract as one field? Then perhaps you should try a different approach;
props.conf
[your sourcetype]
EXTRACT-blah = ^(?<field1>\S+)\s+(?<field2>\S+)\s+(?<field3>\d+\s\w+)\s(?<field4>.*)
/K
Thanks.. This worked!
what have you tried so far, and do you want the date/time to be a single field or broken up?