I have the following issue
I have two types of logs: A & B
A & B are from the same Index, have the same source type and same source (wish of the Client)
BUT they differ in two aspects:
1) the one contains the value "aaa" and the another "bbb"
2) log A has the structure FIELDNAME=VALUE
log B has the structure FIELDNAME = VALUE\
since they belong to the same sourcetype i have no idea how to delete this \ after the value
your search |rex mode=sed field=FIELDNAME "s/\\\$//"
@alex_kh, Does it work for you?