I have some sendmail logs that send the following different entries within the data streams:
disposition=abc123
disposition=abc123, followed by some stuff.
disposition=xyz-123
disposition=xyz-123, followed by some stuff.
And I need to build one REX statement that allows me to call what comes after the "=" sign an errorcode. How can define multiple REX's from one search string?
Here is an example that works, but also pulls too much information after location the errorcode.
index=sendmail | rex "disposition=(?
It pulls everything after the errorcode including addtional characters, words and numbers and I need to grab strong text only.
Any thoughts on how to build a multi REX statement within one search query and defining each found errorcode as an incident?
Perhaps something like "disposition=(?P
Perhaps something like "disposition=(?P