Hi,
I have the following format of Dates in my logs like 2007/01/25 and 2006/12 . i want to extract these dates to a single field called Date. I have written the regular expression like this..
"(?i)/.*?/(?P
but this is extrating only the format 2007/01/25 .. but i couldn't extract 2006/12 ..how can i write a single regular expression to extract both the dates ???
please help
Without knowing what the source looks like, this is a bit more difficult to answer. It also looks like you are using the interactive field extractor feature in Splunk. However, the simplest regex for use with the rex command based on your example would be:
|rex field=yourField "(?<1date>[\d/]+)\s\w+"
Without knowing what the source looks like, this is a bit more difficult to answer. It also looks like you are using the interactive field extractor feature in Splunk. However, the simplest regex for use with the rex command based on your example would be:
|rex field=yourField "(?<1date>[\d/]+)\s\w+"
Thanx Rob 🙂
@rakesh498115
I edited the regex above to match what you are looking for. That should do the job.
I have log events like
event1
2007/02/12 <
asdasdasdasdsadasdasd
asdsdad
event2
2006/12 <
asdas
dsadsadsadsadasdasdsadsa
sadsa