I have an output that looks like this: AV_DATE=Jan-1-2018
I want to be able to just display the date as so: Jan-1-2018
How can I do that?
@ albinortiz , can you test this
| makeresults | eval _raw="AV_DATE=Jan-1-2018"| extract kvdelim="="
OR
| makeresults | eval field="AV_DATE=Jan-1-2018" | rex field=field "AV_DATE=(?<field>.*)"