我是 SPlunk 的新手,试图做一些仪表板,需要帮助来提取特定变量的字段
在我的情况下,我只想将 KB_List":"KB000119050,KB000119026,KB000119036" 值提取到一列
Expected output:
KB_List
KB000119050,KB000119026,KB000119036
我努力了:
| rex field=_raw "\*"KB_List":(?<KB_List>\d+)\*"
在日志中突出显示以下部分
svc_log_ERROR","Impact":4.0,"CategoryId":"94296c474f356a0009019ffd0210c738","hasKBList":"true","lastNumOfAlerts":1,"splunkURL":false,"impactedInstances":"","highestSeverity":"Minor ","来源":"hsym-plyfss01","reqEmail":"true","AlertGroup":"TIBCOP","reqPage":"","KB_List":"KB000119050,KB000119026,KB000119036","reqTicket" :"true","autoTicket":true,"SupportGroup":"TESTPP","Environment":"UAT","Urgency":4.0,"AssetId":"AST000000000159689","LiveSupportGroup":"TESTPP"," sentPageTo":"TESTPP"},"通知":{"":{"requestId":"532938335"}},"":