index=whatever* sourcetype=server earliest=-3d | table USERNAME CLIENT_VERSION_IN |where NOT isnull(SU_USERNAME_IN)|where CLIENT_VERSION_IN=*07_2*
CLIENT_VERSION_IN=*07_2* doesnot seem to work as the value here 'XF_07_2_5474'. Can some one help build a rex or regex so that i could get the data.
In terms more close to your question, with MuS's reply, use:
index=whatever* sourcetype=server earliest=-3d | table USERNAME CLIENT_VERSION_IN | rex field=CLIENT_VERSION_IN "\'(?P<fixedfield>.+)\'" | table CLIENT_VERSION_IN fixedfield
Completely generic for your case as provided.
I must admit, I don't fully understand your intensions but sure this will work:
| eval foo="'XF_07_2_*'" | rex field=foo "\'(?P<myfoo>.+)\'" | table foo myfoo
will result in a table looking like this:
foo myfoo 'XF_07_2_*' XF_07_2_*