05:45:25.985 [http-nio-8080-exec-137] INFO c.b.h.i.s.i.OrderDecompositionServiceImpl - POID=20275475 FOID=TRAFFIC_MGMT,43375717 FOID=CPE,43375719 FOID=RADIUS,43375721 FOID=WCLI,43375723
Either this:
... | rex mode=sed "s/^.*?FOID//"
| rex max_match=0 "=(?<Type>[^,]+),(?<Number>\d+)"
OR this:
... | rex mode=sed "s/^.*? - //g s/FOID=//g s/,/=/g"
| kv
Hi @jayavasge ,
You can try this ...
Your search | rex max_match=0 "FOID\=(?P<type1>[^\,]+)\,(?P<number1>[^\s]+)"
| eval zipped= mvzip(type1,number1,"!!!!!number1=")
| mvexpand zipped
| fields _time zipped
| mvexpand zipped
| rex field=zipped "^(?P<Type>.*)!!!!!number1\=(?P<Number>\d+)"
|table Type Number
for example ,
this is a run anywhere search
| makeresults
| eval data="05:45:25.985 [http-nio-8080-exec-137] INFO c.b.h.i.s.i.OrderDecompositionServiceImpl - POID=20275475 FOID=TRAFFIC_MGMT,43375717 FOID=CPE,43375719 FOID=RADIUS,43375721 FOID=WCLI,43375723"
| rename data as _raw
| rex max_match=0 "FOID\=(?P<type1>[^\,]+)\,(?P<number1>[^\s]+)"
| eval zipped= mvzip(type1,number1,"!!!!!number1=")
| mvexpand zipped
| fields _time zipped
| mvexpand zipped
| rex field=zipped "^(?P<Type>.*)!!!!!number1\=(?P<Number>\d+)"
|table Type Number
let me know if this works...
Hi there, can you let me know what is expected output?
Type Number
TRAFFIC_MGMT 43375717
CPE 43375719
RADIUS 43375721
WCLI 43375723