Hi,
I am newbie to splunk,We are looking to extract a field from below event format.
"PDR Message Listener Completed Processing Message"
From above , we need to extract a field after "PDR Message Listener" as field called status as "Completed", Can someone help extraction using Rex command.
we tried using field extrcation from events ,but it is giving us some false results.
↧