The **rex** command extracts fields on the fly using regular expressions (regex).
Use named capturing groups like `(?<fieldname>regex)` to pull out specific data into a new field.
Unlike `eval`, `rex` matches against raw data and extracts substrings.
| rex field=_raw "Failed password for .* from (?<src_ip>\\d+\\.\\d+\\.\\d+\\.\\d+)"