Feature request: parse: wildcard like "*" that does not assign to a field


1 comment

    Kevin Keech

    Thanks for sending in this request, I like the idea of an alternate non capturing wildcard for the parse anchor.

    Until this can become an option you should be able to do the second option in your sample, then just toss the unwanted field away using the "fields" operator.

    | parse "message: *,*,*." as field1,ignored,field2
    | fields - ignored

    You could also probably do this with a "parse regex" operation to only pull the data into the fields you want.

    | parse regex "message: (?<field1>.*?),.*,(?<field2>.*?)"


