我使用下面的rex表达式在我的原始数据中搜索以下字段:| rex "Address Line 1=(?<address1>[^,]*)" | rex "Address Line 2=(?<address2>[^,]*)" | rex "Address Line 3=(?<address3>[^,]*)" | rex "Address Line 4=(
$token_rex$index=* | rex field _raw "(?i)(?<lorem>lorem+?)|(?<ipsum>ipsum+?)|(?我尝试过使用令牌过滤器$token_rex|s$和$token_rex|n$,但两者都不起作用。我甚至尝试从子搜索中返回值:
index=* | rex field _raw [| makeresults | eval string_rex=$token_<e