Utility Functions - regexp

  1. regexp


  • regexp(pattern, field)
search sContent("@event_type", "@azureSignIn")
let {username="userPrincipalName"}=f("@azureSignIn")
let {}=regexp("(?<name>.*)@(?<domain>.*)",username)

In this example, the command regexp extracts the captured “named group” from the regular expression pattern. For username “”, two new columns “name” and “domain” are added with value “foo” and “”.