Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Can you help me use regex to extract fields that contain 'ssd'?

$
0
0
Hello Splunk, I have the following raw log lines: 1 2019-01-29T15:44:41.184068+00:00 xxx vpxd 4566 - - Event [5650552] [1-1] [2019-01-29T15:44:41.182223Z] [vim.event.VmMigratedEvent] [info] [] [x - x] [5650175] [Migration of virtual machine vm1 from host1, ds_SSD_001 to host1, ds_SSD_002 completed] I'm trying to find all log entries where both fields containing *SSD* (ds_SSD_001, or ds_SSD_002,or ds_SSD_00x) are different. (This basically means that one VM has moved from one datastore to another) I figured I should be using rex to extract the 2 occurrences of *SSD* and compare them | where field1 != field2 I can't manage to find the regex code to extract these fields (I'm very new to regex...)

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>