Hi All,
As I want to retrieve part of the source name and inner join to the other source. I would like to use the regex to get the source. However I am not sure how to write it
Here the source name list
D:\\deploy\\logs\\uat\\20140929101121\\build1.log
//usr//bin//app1//log//dev//20140929100730//build2.log
//usr//bin//app1//log//dev//20140929100728//build1.log
And I would like to get the timestamp in the path.
20140929101121
20140929100730
20140929100728
The regex should be
(\d+)(?=[\\\/]{2}[^\\\/]*$)
But I don't know how to implement to search query.
Regards,
Chris
I found the solution. ..... The regex format is very different from javascript, .net.....
Here's my answer.
sourcetype=XXX| rex field=source "(\d+)(?=[\\\/](?.*)[\\\/]*$)"|table sss source
Hi,
Need help with something similiar..Not able to generate the correct regex for this.
Source files and the needed extractions are shown below.
1) file.1000.1.log --Should return 1
2) file.1000.1.32.log -- Should return 1
3) file.1000.2.log -- Should return 2
4) file.1000.2.16.log --Should return 2
5) file.1000.2.32.log --Should return 2
I found the solution. ..... The regex format is very different from javascript, .net.....
Here's my answer.
sourcetype=XXX| rex field=source "(\d+)(?=[\\\/](?.*)[\\\/]*$)"|table sss source