How to extract the user(splunk) from the below field?
(ABCDEFG\splunk)
Try this
your search | rex field=yourfield "\\\(?<user>\w+)\)"
Other methods
your search | eval user=replace(yourfield, "^.+\\\(\w+)\)","\1")
your search | eval user=rtrim(mvindex(split(yourfield,"\\"),-1),")")
Try this
your search | rex field=yourfield "\\\(?<user>\w+)\)"
Other methods
your search | eval user=replace(yourfield, "^.+\\\(\w+)\)","\1")
your search | eval user=rtrim(mvindex(split(yourfield,"\\"),-1),")")