Hi,
how to extract the field "alert" with the field name action.
help with the regex..
Thanks.
@balu1211Have you tried my answer above? It creates key-value pairs, then extract them.
@yuanliu
We have to create a new field name it's not the existing field.
Thanks..
@ITWhisperer
Could you please figure out the outputs of the above usecases.
Thanks
| rex "\"tag\":\"AKAMAI\/WAF\/(?<akamai_waf>[^\"]+)\""