[2015-11-05 00:48:03,058] [/172.21.21.171:57533] [K123456789] created event: 8
How do I use rex field to extract just the last number on this, for example here, it would be 8? The log format is the same throughout, but the last number is the ID which is what I'm most interested in.
Thanks
Hi aramakrishnan,
You can also try this regex. \d+ will capture digit and $ (dollar sign) indicates the end of the string.
.. | rex "(?<id>\d+$)" | ..
There are probably a few ways to do that. Here's one.
... | rex "event: (?P<ID>\d+)" | ...