Logstash Filtering split


(Brian) #1

How would I filter "fileWriteEvent/username": "domain\bob132" so that I can create a new field
( basically taking out hte domain\)
Username: bob132


#2
    mutate { add_field => { "username" => "domain\bob132" } }
    mutate { gsub => [ "username", ".*[\\]", "" ] }

(Brian) #3

That mutate gsub statement is what i needed. Thank you! . Can you explain that syntax


#4

It says to match zero or more of any-character, followed by one character of the group containing backslash.

Trying to get a single backslash into the configuration can be a challenge. This is a standard trick used in mutate+gsub.