I'd like to get contents between fields. Here is a sample log.
CheckPointCount=N/A,CheckPointRestart=no,CheckPointInterval=5,StatusMsg=Open file "d:\data\Inbound Files\ABCSystems\DIFF.PRN" failed. ,CrlMsg=N/A,StatusDiagCode=08,StatusSeverity=01,
When I use "StatusMsg" in query, only "Open" is selected. I'd like to retrieve all content before "CrlMsg".
How can I retrieve entire StatusMsg?
If the one @masonmorales gave isn't sufficient already Or perhaps to get the comma
as well in the capture try below 🙂
your query to return events
| rex "StatusMsg=(?<statusMsg>.*?)CrlMsg="
| table statusMsg
| rex "StatusMsg=(?<StatusMsg>[^,]+),CrlMsg"