Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I use the rex field to extract the last digit from the time value in my sample data?

$
0
0
[2015-11-05 00:48:03,058] [/172.21.21.171:57533] [K123456789] created event: 8 How do I use rex field to extract just the last number on this, for example here, it would be 8? The log format is the same throughout, but the last number is the ID which is what I'm most interested in. Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>