Hi,
I'm trying to map a nested field from a custom grok expression.
So, instead of using:
(?=.*?Message Type: (?<test1>[^;]+))?
I would like to map test1 to [event][name].
Tried things like:
(?=.*?Message Type: (?<[event][name]>[^;]+))?
(?=.*?Message Type: (?<event.name>[^;]+))?
(?=.*?Message Type: (?<{[event][name]}>[^;]+))?
...
Is that even possible? I know I could rename them later but that's not the idea...
Thanks!