I have a string in this form:
sub = 13433
cf-ipcountry = US
mail = abc.test@gmail.com
ct-remote-user = testaccount
elevatedsession = N
iss = www.google.com
user-agent = Apache-HttpClient/4.5.8 (Java/1.8.0_322)
I want to extracr iss fields value
I tried this but did not work
| rex max_match=0 field=_raw "\/sub \/user-agent \/(?<temp>.*)"
Is this the exact string you have in your event? If so, try
| rex "iss = (?<iss>\S+)"
Is this the exact string you have in your event? If so, try
| rex "iss = (?<iss>\S+)"