Forum Discussion

StefanRadtke's avatar
StefanRadtke
Copper Contributor
May 10, 2021
Solved

Extracting a file Extension from a syslog message

We are sending syslog messages to Azure Monitor where the message body looks like this:     10.220.200.26,groot-1,"AD\alice",smb2,fs_read_data,ok,123,"/source/folder/file.doc","/target/folder/fil...
  • CliveWatson's avatar
    May 10, 2021
    You didn't "extend" / Split first CSVFields

    Syslog
    //| where ProcessName == 'qumulo'
    | extend CSVFields = split(SyslogMessage, ',')
    | extend Path1 = tostring(CSVFields[6])
    | extend FileExt1 = extract((@"\.[^.\/:*?'<>|\r\n]+$"),1,Path1)

Resources