Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Can you help me with a regex expression(multiple in one query)?

$
0
0
Trying to capture multiple groups, basically after the colon MacAddress : 7A:AA:82:31:24:B1 Manufacturer : VENDOR Username : SC32131BN_user IPNET : 11.412.111. PasswordExpires : 11/24/2018 3:44:48 PM Version : CCCS - 1423209 PhysicalDriveSpace : 19.620432424279 TotalRAM : 3.84324242539 DHCPLeaseExpires : 20432424324215.000000-300 DHCPServer : 11.12.234.61 SID : S-1-5-21-432233414-414324275-1810497902-1001 The name would be the field on the left. I tried something like this: | rex "MacAddress\s+\:\s(?P[^\n]*) | Manufacturer\s+\:\s)(?P[^\n]*)" but it doesn't appear to be giving me anything.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>