Hi Team,
I have search in search head which gives output like in snapshot.
Now i want to assign a new field to client no like client 26 , client 31 . All these (client 26, client 31 etc) should have a particular field.
I have tried to used eval command but did not get exact function to be used.
Please help me . Snapshot is attached.
Assuming you want to extract the number into a field called client, you can do that using the rex command:
| rex "client\s+(?<client>\d+)\s+connected"
I think Frank meant - client\s+(?<client>\d+)\s+connected
Oh, yeah, sorry, forgot to post it as code, which makes the triangular brackets disappear. Fixed it 🙂
Fun stuff ; -)
Hi Ddrillic/FrankVI ,
I want to assign output value like "client 26 , client 36" to an another field .
These values should be visible in interesting fields.
That is my question.