The unsturctured log contains many lines and at the end below coverage report, it is not getting captured as a field, even Extract new field, when I tried, it is adding junk data in the fields covering other lines
line1
line2
..
...
line n
============ coverage report ==========
Statements : 34% (20/22)
Is it possible to create a search query which would generate the table like
_time Statements Lines
14-9-2018 34% 56%
Since the coverage report is unstructured not able to capture the details as a field.... any suggestions are welcome.
Thanks!.
Hi @mindia,
you can try this on raw data :
...|rex "Statements : (?<Statements>[^\s+]+).*Lines : (?<Lines>[^\s+]+)"|table _time, Statements , Lines