Hello,
My logs contain some sentence like :
"2014-07-22 14:47:10,783 INFO [LoggingInterceptor]|EXIT: CmsXwbDecodingPayloadDriver.decode() : 15ms"
I want to extract the '15' (from '15ms') in a field "decode_time" and display the result for each corresponding event.
I am cleary not confident with regular expressions.
What should I do ?
Thank you
Something like this should do the job.
rex "(?<decode_time>\d+)ms$"
Try this
your base search | rex ": (?<decode_time>\d+)ms$"
Nice !
Thank you