Hi,
Here is my regex approach:
(?:\"\")(\w+)(?:\"\":)(\"\"[\w\W]+?\"\")(?:,|})
Note: It will not capture values that are not escaped (e.g. ExecutableSize"":1951728). For those values I would write a new extraction.
I had bad experience before with Splunk regex and look ahead/behind.
BR,
Marko P.
... View more