my logs in splunk like:
[ A=xaxxxxx ] [ B=weea case ] [ C=another example 0 ]
How can I get only the string in square bracket after "="
like so: xaxxxxx ; weea case ; another example 0
my rex is: rex field=_raw "(?<New_Field>\[\sC=(.*?)\s\])"
it extract all, include square bracket [...].