I have data that looks like:
20140609 19:14:03 [PERF] [CREATE PLAN START] Action=CreatePlan,
and would like to extract the text between the second pair of brackets, namely in the above line the text "CREATE PLAN START."
I tried rex field=_raw "]s+[=(?
Finally got it right:
rex field=_raw "] [(?
This looks like it might work for you:
rex field=_raw "]\s+\[(?<step>[\w\s]*)\]"