How to use regular expression for an Exception message from a Source=Windows:Application to cut the beginning of the message and display the just unique exception message?
index=indexname source="WinEventLog:Application" CNBD Employee | table _time, host, Exception_Message
Exception_Message :
Dear CNBD Employee: If you see this exception, you should likely splash some cold water on your face and spring to action! The item_number BA11110 on hu_id MX99999 for wh_id ONT was not found. We need to fix this immediately else it might lead to undersells causing a revenue hit.
I'm looking to cut the beginning of my exception message and begin at the sentence below :
The item_number BA11110 on hu_id MX99999 for wh_id ONT was not found. We need to fix this immediately else it might lead to undersells causing a revenue hit.
I'm very green when using regular expression and am trying to get more comfortable using it in my searches
How about trying this if you think its always the first sentence which you want to remove (assumption below is first sentence shall end in . OR ! OR ?
which can be extended based on type of sentence ending punctuation):
index=indexname source="WinEventLog:Application" CNBD Employee
| rex field=Exception_Message "^.*?(\.|\!|\?)\s*(?<exception>.*)"
| table _time, host, exception
How about trying this if you think its always the first sentence which you want to remove (assumption below is first sentence shall end in . OR ! OR ?
which can be extended based on type of sentence ending punctuation):
index=indexname source="WinEventLog:Application" CNBD Employee
| rex field=Exception_Message "^.*?(\.|\!|\?)\s*(?<exception>.*)"
| table _time, host, exception