I'm trying to write a field extraction on the search head using a regex .
the sample data is as follows
EVENT1: abc,firstname.lastname@example.org,password ,127.0.0.1
the fields are comma-delimited whether or not there are values for each fields . In second event, email and type fields have no values(user and ip fields ALWAYS have values)
Can someone assist me in a regex to handle all fields? if the field has no value (email or type) assign no values to the fields .
Thanks in advance.
| rex "(?<user>[^,]*),(?<email>[^,]*),(?<type>[^,]*),(?<ip>[^,]*)"
View solution in original post