How to extract the field values between two same characters.
Event
Axxtalled=xrxnx xx Client\;**12.0.5294**\;15.179.00\;3x/x/2xx\;,
I want to extract 12.0.5294
Hi
Try this,
| makeresults
| eval Axxtalled="xrxnx xx Client\;12.0.5294\;15.179.00\;3x/x/2xx\;,"
| eval result = mvindex(split(Axxtalled,"\;"),1)
Hi @rashid47010 ,
Please check this: https://regex101.com/r/l5xt9s/1
Splunk query:
| makeresults count=1
| eval _raw="Axxtalled=xrxnx xx Client\;12.0.5294\;15.179.00\;3x/x/2xx\;,"
| rex field=_raw "\\\\;(?<myfield>[\d.]+)\\\\;"