Hello,
I am trying to extract a field that is offset by one column:
Event 1: [DT_2.0_REAL][0x80c00002]
Event 2: [0x80c00002]
Event 3: [HONDA_REAL][0x80c00002]
Event 4: [0x80c00002]
As you can see, the [0x80c00002]
is offset by one column here, so the automatic field extraction fails.
How can I adjust the regex to account for this offset? Thanks!
If you are always going for the last one, like this:
... | rex "\[(?<lastBracketedField>[^\]]+)\]$"
Do you need the enclosing brackets? This regex will extract the field without them.
(?P<field>0x[^\]]+)