I have an output of
index=feds | fillnull value="" | table httpRequest.clientIp labels{}.name
If it is always the last item of a multivalue field, you could try something like this
index=feds | fillnull value="" | table httpRequest.clientIp labels{}.name
| rename "labels{}.name" as name
| eval name=mvindex(name, -1)
not always the last 😞
Does it always start with "awswaf:managed"? Or is there some other way to recognise the part you want displayed?
Always with that String
You could try extracting just that part from your events. If you want help doing that, you should share some raw events in a code block </> to preserve formatting.