Hey try this
you can use
\ to escape “
Suppose you have user=“xyz” in the event and you want to extract xyz then you can use below regex
| rex field=_raw “user=\”(?P<user>[^\”])”
You can use regex101.com to learn more !
Let me know if this helps you.
You can escape the double-quote by using a backslash. Here's some sample run-anywhere code:
|makeresults | eval tf="contains a literal quote \" followed by stuff" | rex field=tf "\"(?<after_quote_stuff>.*)"