Hi,
I want to Extarct Filed from Source file and Below are some
Sorce file.
/opt/si/logs/taopwssid1/admin/paas-cli.log.07-11-17
/opt/si/logs/umsawssis1/admin/tcmgr.log
/opt/si/logs/saidwssid2/admin/paas-cli.log.07-11-16
I want to extract below value
taopwssid1
umsawssis1
saidwssid2
How Can i Do this through REX.
Try this.. It will create a new field called host_name
with the extracted fields your looking for
| rex field=source \/opt\/\w+\/\w+\/(?<host_name>\w+)
Try like this
your base search
| rex field=source "^(\/[^\/]+){3}\/(?<YourFieldName>[^\/]+)"
Try this.. It will create a new field called host_name
with the extracted fields your looking for
| rex field=source \/opt\/\w+\/\w+\/(?<host_name>\w+)