id=[ci.fif.3000-67777]
id=[fg.hki.4000-88888]
this the content of file i am working with from this i want only the values(3000 and 4000)please help.....
Extract the values as fields in Splunk. Quickest way is to use rex
:
... | rex "\.(?<myvalue>\d+)-\d+\]"
This command creates a field myfield
from your data when you include the command in your search.
i got right value
Thanks Ayn...