hi,
i am trying to figure out how to parse such a log file:
from server 1
NAME ; JAMES
PERFORMANCE ; 90/100
from server 1
NAME ; TONY
SUCCESS ; 60/80
from host 1
NAME ; ANNA
PERFORMANCE ; 70/100
as you can see, the name of the fields are changing and so are the values.
The event delimiter BREAK_ONLY_BEFORE is "from server".
tny idea how to parse this ?
thanks.
heloma.
Try this in your props.conf
REGEX = ([^;]*) ; (.*)
FORMAT = $1::$2
Try this in your props.conf
REGEX = ([^;]*) ; (.*)
FORMAT = $1::$2
no luck!
what I am looking for, is to auto-extract NAME, PERFORMANCE, SUCESS as new fields and 90/100 , etc as values.
any hint ?
thks
My apologies, the REGEX and FORMAT attributes should go in transforms.conf. Like this:
[semicolon]
REGEX = ([^;]*) ; (.*)
FORMAT = $1::$2
Then put a reference to the transform in props.conf:
[MySourcetype]
TRANSFORMS-semicolon-separated = semicolon
Excellent! thanks.