Scenario, I have a field (msg) below and I need to extract the user id which is user = [abcdefg]
field msg = AAA user accounting Successful : server = 192.168.0.1 : user = abcdefg
index = main | rex field=msg [?] ....
I need the abcdefg portion.
Assuming the value is terminated by a space, this should do the job.
... | rex field=msg "user = (?<user>[^ ]*)" | ...