I'm trying to remove everything after the first colon that appears in a line and group by that value.
An example of the data:
ComputerName; User1: your job has been processed.
ComputerName; User3: your job has failed.
ComputerName; User2: your job is processing.
I'm able to remove the computer name using:
| rex "ComputerName;(?<UsersPlus>[^$]+)"
However, I'm not sure how to keep the username and remove everything after the colon so I can group by the username, (User1, User2, and User3)
Any help would be much appreciated.
ComputerName;\s?(?<UsersPlus>[^:]+)
Thanks, this worked beautifully.