EM-Event Rule Regular expression to capture part of the string to retrieve and populate on Node

jpn
Giga Contributor

Hello,

 

Can some one kindly help on how to retrieve and populate the Node field from "firstLevelContainerId": field variable of 3rd String I.e sbsv2corpinfra which is again in double quotes.when i tried with all types of expression, still posting <<unknown>> on Alert Node field and binding failure.also i need to capture message key using this combination as "SourceType"+"firstLevelContainerID" of 3rd String I,e.sbsc2corpinfra.

 

"sourceType": "Microsoft.Storage/storageAccounts/fileServices/shares",
"category": "Jobs",
"firstLevelContainerId": "Storage;RG-LENEL-PRODVM;sbsv2corpinfra",

 

PFA:Image raw Json event format from MS LogAnalytics.BackupFailure_ER.jpg

Thanks in Advance,

Prakash

1 REPLY 1

Abbas_5
Tera Sage
Tera Sage

Hello @jpn,
Please refer to the below link:
https://www.servicenow.com/community/itom-blog/become-awesome-with-event-rules/ba-p/2274485

 

If it is helpful, please mark it as a thumbs-up and accept the correct solution.

Thanks & Regards,
Abbas Shaik