What version of SIEM software are you running? This will help determine how much / what context of Regex you might be able to use.
The first thing you might try is testing out your regex on your ESM's main window "Filter" to make sure you have workable syntax.
Also, not all fields are searchable via regex, I am not sure if there is a list of fields that it works with.
In the initial release that allows regex, you could only use "contains(regex expression goes here)"
From what I understand, version 9.4.x allows for "regex(regex expression goes here)"
Thanks rth67 working!