Hiiii
How to extract the single field with multiple values?
Like status is active, failed, cancelled, deactivated, forwarded, reversed
I have created a regex but it is only looking for active not for remaining status...
I used your data to formulate a sample test.
| rex field=a "newstp - (?<status>\S*)
Tell me if this works
| rex field=a "\d{4}\-\d{2}\-\d{2}\s\d{2}\:\d{2}\:\d{2}\,\d{3}\"\;\"(?<field1>[^\"]*)\"\;\"(?<field2>[^\"]*)\"\;\".*\d{4}\-\d{2}\-\d{2}\s\d{2}\:\d{2}\:\d{2}\,\d{3}\"\;\"\d*\"\;\"(?<field3>[^\"]*)"
Hiii tiagofbmm,
I posted a new query, I didn't get a correct response from anyone.. I hope, you will answer to my query..
I have created the fields like A B C.... Now I want to merge A and B fields by creating new field...
Like D=A+B... Can I get any idea on this???
I tried doing this like | eval report= A. "-" .B this is working but we can't run SPL Query everytime...
I used your data to formulate a sample test.
| rex field=a "newstp - (?<status>\S*)
Tell me if this works
If you don't mind can you also help on more two fields?
shoot, I'll help if I can
could you paste here a sample of the data you're looking at?