Parse directory name regex

(Sonne) #1

Hello. I have the logline
2015.10.05 18:32:25.913:Process cannot access the file 'file.txt' because it is being used by another process

I have written the grok:


I need to parse name of directory in the brackets : . I need only parse a directory name after "Log" folder. Directory name could be named as 3-digit name. Folder's name should be written to "fldrname" field. After parsing

need to be deleted from @message. I will be appreciate for any help.

(Magnus Bäck) #2

So you want C:\AR\Log\178 in the fldrname field? Match everything in the string up until the last backslash. The last backslash is the backslash that isn't followed by another backslash. Untested suggestion:


(Sonne) #3

I want only 178 in fldrname

(Magnus Bäck) #4

Slight variation then:


(Sonne) #5

Thank you. It's working.

(system) #6