Ex : hello how are you. pls modify the request and update. modify request cant be done and failed.
You can use rex to update the existing field or create new field -
Example :
| makeresults | eval message="hello how are you. pls modify the request and update. modify request cant be done and failed." | rex field=message "(?<message>modify.+)"
Usage : <your search> | rex field=message "(?<modified_message>modify.+)"
You can use rex to update the existing field or create new field -
Example :
| makeresults | eval message="hello how are you. pls modify the request and update. modify request cant be done and failed." | rex field=message "(?<message>modify.+)"
Usage : <your search> | rex field=message "(?<modified_message>modify.+)"