I'm trying to find a way to catch the number 0018F3D97D02BBA0517E001A&0 which before the last backslash.
I put an extract of the line I want to a reg on it.
Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR\Disk&Ven_Kingston&Prod_DT_R500&Rev_PMAP\0018F3D97D02BBA0517E001A&0
The reg command I used is the following:
| rex field=_raw "USBSTOR.*_(?<USBID>......?)"|
I just want to extract all data after the last backslash.
If that code is the last text in the event, how about:
| rex "(?<USBID>[^\\]+)$"