Hi vrmandadi,
if the events are always in the format of the example you can use this regex:
your search here to get the events
| rex max_match=0 field=message "Method:\s(?<Method>[^\s]+)\s\|\sClass:\s(?<Class>[^\s]+)"
| table _time Method Class
Hope this helps ...
cheers, MuS
Hi vrmandadi,
if the events are always in the format of the example you can use this regex:
your search here to get the events
| rex max_match=0 field=message "Method:\s(?<Method>[^\s]+)\s\|\sClass:\s(?<Class>[^\s]+)"
| table _time Method Class
Hope this helps ...
cheers, MuS
Thanks a lot Mus
^\w+\s+.\s+\w+.\s+\w+\s+\w+.\s+\w+.\s+(?\w+\s+).\s+\w+.\s+(?\w+)
This is a "Greedy" RegEx - Regex101.com is your friend!