Splunk Search

What is the rex command to extract my field?

what is the rex command to extract the below highlighted field.
2015-12-22 22:40:13 ID="87602", DataName="sap01 "DDC - PVD - UDB SPP42 (LDTC1)"", DataType="DB2"

0 Karma

SplunkTrust
SplunkTrust

Try this search query

... | rex field=Data_Name "\s(?<field>[^\s]+)\s(?=\()" | ...
---
If this reply helps you, an upvote would be appreciated.