If that is the exact regex and you are talking about using the rex command, then
| rex "(?<new_field>(?<=\:\[)(.*)(?=\]))"
will extract the data between the [] into new_field
Worked like a charm, thank you !
If that is the exact regex and you are talking about using the rex command, then
| rex "(?<new_field>(?<=\:\[)(.*)(?=\]))"
will extract the data between the [] into new_field