one of my field contains one big string as shown below
Using rex expression i wanted to extract the value of doc_name which is embedded inside the params field - the value is equal to whatever comes in till we hit )
sourcetype = abc.log | fields params | rex "doc_name:<?mydocname>+\ - i tried this - its not working..wanted to extract it in mydocname and sort by that field
Does this work?
| rex "doc_name:\"(?<mydocname>[^+]+)"
You may also need to specify the field for the rex if it not coming from _raw like so.
| rex field=params "doc_name:\"(?<mydocname>[^+]+)"