I'm running the following command:
host=Computername AND EventCode=1309 | rename "Exception message" as Exception_message | dedup Application_Path | table Application_Path Exception_message
But it still won't recognize Exception message. If I expand the results, here is a snippet of the returned data:
Exception information: Exception type: HttpException Exception message: Server cannot set status after HTTP headers have been sent.
I'd like to create a table showing the Application Path and the Exception message, but I can't get it to recognize my field. Help! Thanks in advance.
Looks like this is a windows log file. Try this:
host=Computername EventCode=1309 | rex field=_raw "Exception message:(?<exception_message>[^\r\n]*)"| dedup Application_Path| table Application_Path exception_message
Looks like this is a windows log file. Try this:
host=Computername EventCode=1309 | rex field=_raw "Exception message:(?<exception_message>[^\r\n]*)"| dedup Application_Path| table Application_Path exception_message
Glad it worked for you, please accept the answer if it worked for you.
Brilliant! That worked perfectly. Thanks!
I am assuming you already have a field extraction or transform for this sourcetype and all the fields you are referencing?