splunk: how to use enable rex command?

  Kiến thức lập trình

a_part=”1/1/1″
b_part=”e1/1/1 to ccc-ct-3102 2/2/2″ or b_part=”i1/1/1 to ccc-ct-3102 2/2/2″ or b_part=”1/1/1 to ccc-ct-3102 2/2/2″
c_part=”ccc-ct-3102 2/2/2″
can use this
| rex field=b_part “(?i)$b_parts+(?<c_part>.*)”
how use $a_part ?

| rex field=B_part “(?i)$A_parts+(?<c_part>.+)”

New contributor

世宏楊 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.

Theme wordpress giá rẻ Theme wordpress giá rẻ Thiết kế website

LEAVE A COMMENT