I would like to extract a new field from unstructured data. FX does not help for 100%, so I would like to use regex instead.
Is it possible to extract a string that appears after a specific word? For example, I always want to extract the string that appears after the word testlog:
Sample events (the value for my new fieldA should always be the string after testlog):
1551079647 the testlog 13000 entered the system
1551079652 this is a testlog for fieldextraction
Result of the field extraction:
Thanks in advance