I want to make a field extraction by the name of Action to show this whole text ,'update ggsourceadmin.monitor set ORACLE_TIME = CURRENT_TIMESTAMP WHERE TABLE_PK = 1',; how should I extract?
You need to show us the entire raw event.
You would have to show us the surrounding text, or examples of different versions, for us to know what to focus on in building the regex
.
One thing that I would check on is whether that whole SQL statement ended in a semicolon. If so, that makes it pretty easy to know when to stop. Assuming there is one, then this rex
would do it.
| rex "(i)(?update [^;]+;)"