I am trying to extract the name of log output but struggling with how to. I have this query
<query>index=dap ("user login Time") </query>
That I have a log that outputs
log: [2m2021-11-19-t18:27:42.996z [22m [34m auth [39m [32minfo user login time, Justin [ ...
stream: stdout
time: 2021-11-19-t18:2742.99648142z
I want to output only the time and username:
Time: user:
2021-11-19-t18:27:42. Time, Justin
Assuming time has already been extracted (_time) on indexing, you could try this to get the user
| rex "user login\s+(?<user>[^\[]+)\s\["