I need to fetch the 'sid' value from the below JSON.
For that I prepared the below query, but it is not working.
|rex field=_raw "sid\":\"(?P<sid>.[^\"\,\"]*)"
|stats count by sid
Amongst other things, you were missing a space. but it can be simplified to
rex "sid\":\s\"(?P<sid>[^\"]*)"
Amongst other things, you were missing a space. but it can be simplified to
rex "sid\":\s\"(?P<sid>[^\"]*)"