i want to retrive
BLOCKED_PARENT (This item is blocked because its parent cannot syndicate.) message from the below raw event. Please help me with this.
SC TYPE: BLOCKED_PARENT (This item is blocked because its parent cannot syndicate.)n*SC*
Try this
rex "(?<msg>BLOCKED_PARENT \(.*\))"
Try this
rex "(?<msg>BLOCKED_PARENT \(.*\))"
In case there is another set of parentheses in the even:
rex "(?<msg>BLOCKED_PARENT \([^\)]*\))"
And if you only want the message part of the BLOCKED_PARENT message:
rex "BLOCKED_PARENT\s+\((?P<message>[^\)]*)"