Hello,
I need to parse out the message field in a windows event log.
For example:
Message=Successful Network Logon: User Name: USER Domain: DOMAIN Logon ID: () Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos
I need to be able to parse on Logon Type: 3 within transforms.conf but none of my regex's are returning what I want (or any events for that matter).
Thanks for any help
Kevin