Hi I have a search that returns the following
. Adobe Acrobat XI Pro DSC
.. Adobe Flash Player ActiveX DSC
... Adobe Flash Player NPAPI
... Adobe Reader XI (..)
.. Adobe Shockwave Player
... Atmel Touchscreen Power
Is there a command that could get rid of the leading periods? They go from just one period up to three of them
Try this please using rex
assuming your fieild is called myField
and data of interest will be collected in field called stringOfInterest
:
your query to return events
| rex field=myField "\.+(?<stringOfInterest>.*)"
| table stringOfInterest
Sure, here's a standalone example of what you could do with the rex command:
| gentimes start=-1 | eval xyzzy=".. Adobe Shockwave Player" | rex field=xyzzy mode=sed "s/^\.+(\s+)?//"
This will remove any leading periods and whitespace after the periods. There are probably faster ways to do it but this should work pretty well. Good luck!