Hi,
in my logs I have a field named report that contains a lot of informations:
Report=Windows Failed\\Passed_Conditions[]:Failed_Conditions[antivirus_update]:Skipped_Conditions[])\,MACAddress=XXXXXXXXXX\,Framed-IP-Address=XXXXX\.
What I need is only the Failed_Conditions vector, so the content between []. The content could be different so I think I need a regex.
Thank you in advance!!
@marco_massari11, please try below regex
| rex field=Report "Failed_Conditions\[(?<Failed_Conditions>[^\]]+)"
@marco_massari11, please try below regex
| rex field=Report "Failed_Conditions\[(?<Failed_Conditions>[^\]]+)"